Regulatory & compliance⏱ ~1 minNOSEDKFIEU

ISO/IEC 27001

The international standard for information security management systems. It sets requirements for how security is governed, not for which products are used.

ISO/IEC 27001 describes how an organisation should build and run an information security management system - an ISMSThe management system - policies, roles, risk assessments and procedures - that ISO 27001 sets requirements for. The certification proves the ISMS actually works.. The standard is deliberately technology-neutral: it does not say which firewall to have, but that you must have assessed risk, chosen controls from that assessment, documented the choices, and reviewed them regularly. Certification against it is done by an accredited third party and covers a defined scope - which parts of the business, which services, which locations. It is worth reading the scope when assessing a supplier's certificate, because certification covering head office does not necessarily say anything about the service you are buying. The standard does not replace sector requirements either: in the power industry, preparedness regulations and NIS2EU directive on network and information security - imposes strict security requirements on critical infrastructure. apply in addition, not instead.

SecurityStandardCompliance