Information-security management systems

ISO/IEC 27001:2022

A clear, review-led credential for organisations demonstrating their information-security management practices.

The standard in context

What is ISO/IEC 27001?

ISO/IEC 27001 is an international standard for information security management systems. It provides requirements for managing risks to information an organisation owns, uses, processes, or makes available to others.

The standard supports a systematic approach to confidentiality, integrity, and availability. Rather than prescribing one technical solution, it expects an organisation to understand its context, assess risk, choose suitable controls, and continually improve.

Important clarification: ISO develops and publishes standards. ISO does not itself certify organisations or operate this programme.

What an ISMS brings together

Security that is connected to how the organisation operates.

An effective ISMS is supported by accountable leadership, repeatable risk practices, suitable safeguards, and evidence that the system is reviewed and improved.

A

Governance

Policies, roles, objectives, and management review make information security a leadership responsibility.

R

Risk treatment

Risk assessment supports informed decisions about controls, ownership, and residual risk.

I

Improvement

Internal audit, incident learning, measurement, and corrective action help the system stay relevant.

Ready to learn more?

Understand the requirements before you apply.

Use the readiness guide to map the main management-system themes and the types of evidence an organisation commonly prepares.