The standard in context
What is ISO/IEC 27001?
ISO/IEC 27001 is an international standard for information security management systems. It provides requirements for managing risks to information an organisation owns, uses, processes, or makes available to others.
The standard supports a systematic approach to confidentiality, integrity, and availability. Rather than prescribing one technical solution, it expects an organisation to understand its context, assess risk, choose suitable controls, and continually improve.