ISO/IEC 27001 is an international standard that specifies requirements for establishing and operating an Information Security Management System (ISMS).
ISO/IEC 27001 is an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) within the context of an organization.
The standard defines a formal management system framework for:
Organizations can implement ISO/IEC 27001 as an internal reference framework or may undergo an independent audit to be certified as conforming to the standard.