ISO 27001 is an international standard that specifies requirements for establishing, implementing, maintaining, and improving an information security management system (ISMS).
ISO 27001 is an international standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It formally specifies requirements for an Information Security Management System (ISMS).
The standard defines how an organization should:
Organizations can implement ISO 27001 internally or seek independent certification by an accredited certification body to demonstrate that their ISMS conforms to the standard’s requirements.