Definition
ISO/IEC 27001 is an international standard specifying requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS).
Human Explanation
It describes how an organisation should manage Information Security to identify and control Risk systematically.
Why it Matters
It provides a globally recognised management framework and supports Trust among customers, partners and regulators.
Conceptual Boundary
ISO/IEC 27001 does not prescribe particular security technologies or products. It defines management system requirements and leaves implementation choices to the organisation.
Practical Perspective
Certification does not mean an organisation is completely secure. It confirms that a structured Information Security Management System is in place.