AiVibe

Cybersecurity & Compliance

ISO/IEC 27001

The international standard that specifies requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), against which organisations can be independently certified.

ISO/IEC 27001 defines a management system rather than a fixed set of technologies. An organisation determines its context and the scope of its ISMS, assesses information security risks, selects controls to treat them and records its decisions in a Statement of Applicability. The current edition, ISO/IEC 27001:2022, includes in Annex A a list of 93 reference controls grouped into organisational, people, physical and technological themes, against which the selected controls must be compared so that none is overlooked.

Independent certification bodies grant certification after a two-stage initial audit, followed by surveillance audits and recertification on a three-year cycle. Customers, regulators and supply-chain partners often treat certification as evidence that information security is managed systematically, and it is a common requirement in IT services, software, cloud and outsourcing contracts.

The standard follows the harmonised structure shared with ISO 9001 and other ISO management system standards, which simplifies integrated management systems. Guidance on implementing the controls is given in ISO/IEC 27002, and guidance on information security risk management in ISO/IEC 27005. Certification demonstrates a functioning management system within the defined scope; it does not guarantee that no security incident will occur.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Terms that refer to ISO/IEC 27001

Ask AiMuruga can explain ISO/IEC 27001 for your plant, product or security programme, and draw how it fits.