ISO 27001
ISO 27001 is the leading international standard for information security management systems. It defines requirements for how organizations systematically establish, operate and continuously improve information security.
The approach is risk-based: starting from a risk assessment, the organization selects appropriate controls from Annex A of the standard (in the 2022 revision structured into four themes: organizational, people, physical, technological) and documents their implementation. Certification by accredited bodies confirms conformity and is increasingly required in tenders and supplier assessments – regular surveillance and recertification audits ensure effectiveness over time.
The basis of certification is a living ISMS; the ongoing collection of evidence for the required controls can be largely automated with Compliance Automation. For many organizations, ISO 27001 is thus the most practicable way to anchor information security internally and demonstrate it externally.