It requires an organization to define the ISMS scope, understand relevant context and interested-party requirements, assess and treat information-security risk, assign leadership and resources, operate controls, evaluate performance, correct nonconformities, and improve the management system.
The current edition is ISO/IEC 27001:2022, with Amendment 1:2024 on climate-action changes. Annex A supplies a reference control set for comparison during risk treatment; the organization documents necessary controls, their implementation status, and inclusion or exclusion rationale in its Statement of Applicability.
Key points
Scope the systemDefine the organizational boundaries, activities, information, technology, locations, interfaces, and dependencies covered by the ISMS and make exclusions or interfaces clear.
Manage riskEstablish repeatable criteria, assess risks, choose treatments and control objectives, assign owners, accept residual risk through appropriate authority, and monitor change.
Evaluate assuranceUse internal audits, management review, objectives, measurements, corrective action, and competent independent certification where certification serves a business or contractual need.
Important limitationImplementation or certification does not prove that every system is secure, every control is effective, or every legal obligation is met. A certificate covers its stated organization, ISMS scope, standard edition, and validity period; ISO does not audit organizations or issue certificates.