ISO 27001:2022
Region
Global (ISO)
Focus
Organisational Management
Description
ISO/IEC 27001 is the world's best-known standard for information security management systems (ISMS). It defines requirements an ISMS must meet. The ISO/IEC 27001 standard provides companies of any size and from all sectors of activity with guidance for establishing, implementing, maintaining and continually improving an information security management system. Conformity with ISO/IEC 27001 means that an organization or business has put in place a system to manage risks related to the security of data owned or handled by the company, and that this system respects all the best practices and principles enshrined in this International Standard.
Key Details
- Developed by the International Organization for Standardization (ISO).
- Focuses on confidentiality, integrity, and availability (CIA) of information assets.
- Includes requirements for risk assessment, control implementation, and continuous improvement of information security management systems (ISMS).
- Aligns with best practices for regulatory compliance and risk management frameworks.