What is ISO/IEC 27001?

ISO/IEC 27001 is the world's best-known standard for information security management systems (ISMS). It defines requirements an ISMS must meet. The ISO/IEC 27001 standard provides companies of any size and from all sectors of activity with guidance for establishing, implementing, maintaining and continually improving an information security management system. Conformity with ISO/IEC 27001 means that an organization or business has put in place a system to manage risks related to the security of data owned or handled by the company, and that this system respects all the best practices and principles enshrined in this International Standard.

Why is ISO/IEC 27001 important?

With cyber-crime on the rise and new threats constantly emerging, it can seem difficult or even impossible to manage cyber-risks. ISO/IEC 27001 helps organizations become risk-aware and proactively identify and address weaknesses. ISO/IEC 27001 promotes a holistic approach to information security: vetting people, policies and technology. An information security management system implemented according to this standard is a tool for risk management, cyber-resilience and operational excellence.

Who is ISO/IEC 27001 - Information security management systems for?

Information security professionals and management across the public and private sectors and commercial and non-profit organizations, as long as they create, collect, process, store, transmit and dispose of information in various forms including electronic, physical and verbal (e.g. conversations and presentations). Typical users will be:
  • Chief Information Security Officers (CISOs)
  • Cyber security risk analysts/advisors
  • Information security consultants
  • Risk managers in compliance and information security
  • What does ISO/IEC 27001 - Information security management systems cover?

    ISO/IEC 27001 specifies requirements for:
  • Establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented ISMS within the context of the organization’s overall business risks.
  • The implementation of security controls customized to the needs of individual organizations .

    The requirements set out in ISO/IEC 27001 are generic and intended to be applicable to all organizations, regardless of type, size and nature.
  • Why should you use ISO/IEC 27001 - Information security management systems?

    • BS EN ISO/IEC 27001 helps organizations secure their information assets, operate efficiently and build their resilience

    • It mandates the creation of an ISMS that is proportionate to each business’s risk profile

    • It reflects the up-to-date consensus of industry experts, including the latest control management best practices

    • It shows stakeholders that your ISMS is operating to the highest standard and builds confidence in your business

    • The reordering of clauses in line with ISO’s harmonized structure make it easier to integrate the implementation of this standard with other ISO management systems

    • It underpins stronger business continuity management and compliance

    • It can reduce information security costs

    • It can be a vehicle for effective staff training and awareness of information security issues

    What’s new about ISO/IEC 27001:2022?

    This is a revision of ISO/IEC 27001:2013. The significance of the new (third) edition ISO/IEC 27001:2022 is to realign it with ISO/IEC 27002:2022 Information Security Controls. Therefore, it incorporates the revisions of:
  • ISO/IEC 27001:2013
  • ISO/IEC 27001:2013/Cor 1:2014 (correction to Annex A)
  • ISO/IEC 27001:2013/Cor 1:2015 (correction of the ambiguity in one of the requirements)

    And the merge of:
  • ISO/IEC 27001:2013/DAmd 1 (which has replaced Annex A in its entirety)