home / guides / iso-27001

Frameworks and controls · ISO and IEC

ISO/IEC 27001 information security management

The international standard for running an information security management system, with third-party certification.

Who this applies to

Organizations that need an independently certified security program, often to satisfy customers or tenders.

What to know

  • It specifies a management system: scope, risk assessment, treatment, objectives, internal audit, and management review.
  • A catalog of controls supports the system, and the organization chooses which apply through its risk assessment.
  • Certification is granted by accredited certification bodies after an external audit, and is renewed through surveillance audits.
  • The standard text is copyrighted and sold by ISO. This site summarizes it and does not reproduce it.

What to do

  • Define a realistic scope before you buy anything.
  • Run the risk assessment honestly. Auditors check that it drives your choices.
  • Choose an accredited certification body and ask about their experience in your sector.

Sources

Reviewed October 2026.