Who this applies to
Organizations that need an independently certified security program, often to satisfy customers or tenders.
What to know
- It specifies a management system: scope, risk assessment, treatment, objectives, internal audit, and management review.
- A catalog of controls supports the system, and the organization chooses which apply through its risk assessment.
- Certification is granted by accredited certification bodies after an external audit, and is renewed through surveillance audits.
- The standard text is copyrighted and sold by ISO. This site summarizes it and does not reproduce it.
What to do
- Define a realistic scope before you buy anything.
- Run the risk assessment honestly. Auditors check that it drives your choices.
- Choose an accredited certification body and ask about their experience in your sector.
This guide is a plain-language summary for general information. It is not legal advice and it does not replace the official source. Requirements change, so check the linked source before you act.