Management Systems

ISO/IEC 27001

Information Security Management Systems

Formal standard Global ISO/IEC JTC 1/SC 27 Since 2005

The requirements standard for an information security management system: scope, risk assessment, risk treatment, the Annex A control set, and the management processes that keep it alive.

It is the anchor certification of the compliance world. NIS2, DORA and sectoral supervisors do not mandate it by name, but an accredited 27001 certificate is the artefact most readily accepted as evidence that a management system exists.

At a glance

Category
Management Systems
Jurisdiction
Global
Governance
ISO/IEC JTC 1/SC 27
Status
ISO/IEC 27001:2022 current; certifiable
First released
2005

Links

Related frameworks

Other entries under Management Systems.

See ISO/IEC 27001 in context

Open the interactive Data Landscape for Regulation to compare ISO/IEC 27001 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.