ISO/IEC 27001 specifies the requirements for an ISMS: scope, leadership, planning, support, operation, performance evaluation and improvement.
Annex A lists 93 reference controls grouped in four themes: Organisational, People, Physical, Technological. Guidance on implementing them is in the companion standard ISO/IEC 27002:2022.
Organisations can be independently certified by an accredited certification body.
Any organisation, of any size or sector, that wants a systematic approach to information security.
Frequently required by customers, regulators and partners as a supplier-assurance baseline.
Define ISMS scope and context; leadership commitment and information-security policy.
Risk assessment and risk treatment against Annex A controls; Statement of Applicability.
Competence, awareness, documented information, operational planning.
Monitoring, internal audit, management review, nonconformity and continual improvement.
- 2005-10-14First edition
- 2013-10-01Second edition
- 2022-10-25Current edition (2022)
- 2025-10-31Deadline to transition existing ISO/IEC 27001:2013 certificates to the 2022 edition (IAF MD 26)
License · ISO/IEC standards are copyrighted. Clause text must be purchased from ISO or a national member body; Nix2 does not redistribute clause text.