Management Systems
ISO/IEC 27001
Information Security Management Systems
The requirements standard for an information security management system: scope, risk assessment, risk treatment, the Annex A control set, and the management processes that keep it alive.
It is the anchor certification of the compliance world. NIS2, DORA and sectoral supervisors do not mandate it by name, but an accredited 27001 certificate is the artefact most readily accepted as evidence that a management system exists.
At a glance
- Category
- Management Systems
- Jurisdiction
- Global
- Governance
- ISO/IEC JTC 1/SC 27
- Status
- ISO/IEC 27001:2022 current; certifiable
- First released
- 2005
Links
Related frameworks
Other entries under Management Systems.
- NIST CSF: Cybersecurity Framework 2.0
- NIST RMF: Risk Management Framework (SP 800-37)
- Grundschutz: BSI IT-Grundschutz
See ISO/IEC 27001 in context
Open the interactive Data Landscape for Regulation to compare ISO/IEC 27001 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.