Launching soon — get early access:
Ethics & Safety

ISO 27001

Definition

An international standard specifying requirements for an information security management system (ISMS) to keep sensitive data secure.

In-Depth Explanation

ISO/IEC 27001, jointly published by ISO and IEC, defines how an organization should establish, operate, monitor, and continually improve an ISMS using a risk-management process. Certification is granted by accredited bodies such as BSI or DNV and follows a three-year cycle with annual surveillance audits. It preserves the confidentiality, integrity, and availability of information. Vendors often pursue it alongside SOC 2, as the two frameworks overlap significantly.

Real-World Example

A cloud provider earns ISO 27001 certification from an accredited auditor to assure customers its security controls meet an international benchmark.

3 views0 found helpful