Nix2
Back to Nix2
Standard·International (ISO/IEC)

ISO 27001

ISO/IEC 27001:2022 — Information security management systems

The international standard for establishing, operating and continually improving an Information Security Management System (ISMS).

Official sources ↓
Current edition published October 2022
Scroll
Overview

ISO/IEC 27001 specifies the requirements for an ISMS: scope, leadership, planning, support, operation, performance evaluation and improvement.

Annex A lists 93 reference controls grouped in four themes: Organisational, People, Physical, Technological. Guidance on implementing them is in the companion standard ISO/IEC 27002:2022.

Organisations can be independently certified by an accredited certification body.

Who it applies to
01

Any organisation, of any size or sector, that wants a systematic approach to information security.

02

Frequently required by customers, regulators and partners as a supplier-assurance baseline.

Core obligations
Duty · 01

Define ISMS scope and context; leadership commitment and information-security policy.

Duty · 02

Risk assessment and risk treatment against Annex A controls; Statement of Applicability.

Duty · 03

Competence, awareness, documented information, operational planning.

Duty · 04

Monitoring, internal audit, management review, nonconformity and continual improvement.

Timeline
  1. 2005-10-14
    First edition
  2. 2013-10-01
    Second edition
  3. 2022-10-25
    Current edition (2022)
  4. 2025-10-31
    Deadline to transition existing ISO/IEC 27001:2013 certificates to the 2022 edition (IAF MD 26)
Official sources

License · ISO/IEC standards are copyrighted. Clause text must be purchased from ISO or a national member body; Nix2 does not redistribute clause text.

Explore other frameworks