ISO/IEC 27001
The international standard that specifies requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), against which organisations can be independently certified.
ISO/IEC 27001 defines a management system rather than a fixed set of technologies. An organisation determines its context and the scope of its ISMS, assesses information security risks, selects controls to treat them and records its decisions in a Statement of Applicability. The current edition, ISO/IEC 27001:2022, includes in Annex A a list of 93 reference controls grouped into organisational, people, physical and technological themes, against which the selected controls must be compared so that none is overlooked.
Independent certification bodies grant certification after a two-stage initial audit, followed by surveillance audits and recertification on a three-year cycle. Customers, regulators and supply-chain partners often treat certification as evidence that information security is managed systematically, and it is a common requirement in IT services, software, cloud and outsourcing contracts.
The standard follows the harmonised structure shared with ISO 9001 and other ISO management system standards, which simplifies integrated management systems. Guidance on implementing the controls is given in ISO/IEC 27002, and guidance on information security risk management in ISO/IEC 27005. Certification demonstrates a functioning management system within the defined scope; it does not guarantee that no security incident will occur.
Key points
- Specifies ISMS requirements built on risk assessment and risk treatment.
- The 2022 edition lists 93 reference controls in Annex A across four themes.
- Certification follows a three-year cycle with periodic surveillance audits.
- Certification covers only the processes and sites within the defined ISMS scope.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- ISO/IEC 27002Cybersecurity & Compliance
- SOC 2Cybersecurity & Compliance
- Compliance Gap AnalysisCybersecurity & Compliance
- NIST Cybersecurity Framework (CSF)Cybersecurity & Compliance
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- NIS2 DirectiveCybersecurity & Compliance
Terms that refer to ISO/IEC 27001
- Digital Personal Data Protection Act, 2023 (DPDP Act)Cybersecurity & Compliance
- Identity and Access Management (IAM)Cloud & AI Infrastructure
- IT vs OT SecurityOT & Industrial Cybersecurity
- Principle of Least PrivilegeCybersecurity & Compliance
- Responsible AIAI & Machine Learning
- Security Awareness TrainingCybersecurity & Compliance
- Shared Responsibility ModelCloud & AI Infrastructure
- Software as a Service (SaaS)Cloud & AI Infrastructure