# What is ISO/IEC 27001?

> ISO/IEC 27001 is an international requirements standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

- Canonical URL: https://yellowcube.eu/glossary/international-organization-for-standardization-international-electrotechnical-commission-27001/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It requires an organization to define the ISMS scope, understand relevant context and interested-party requirements, assess and treat information-security risk, assign leadership and resources, operate controls, evaluate performance, correct nonconformities, and improve the management system.

The current edition is ISO/IEC 27001:2022, with Amendment 1:2024 on climate-action changes. Annex A supplies a reference control set for comparison during risk treatment; the organization documents necessary controls, their implementation status, and inclusion or exclusion rationale in its Statement of Applicability.

### Key points

- **Scope the system:** Define the organizational boundaries, activities, information, technology, locations, interfaces, and dependencies covered by the ISMS and make exclusions or interfaces clear.
- **Manage risk:** Establish repeatable criteria, assess risks, choose treatments and control objectives, assign owners, accept residual risk through appropriate authority, and monitor change.
- **Evaluate assurance:** Use internal audits, management review, objectives, measurements, corrective action, and competent independent certification where certification serves a business or contractual need.
- **Important limitation:** Implementation or certification does not prove that every system is secure, every control is effective, or every legal obligation is met. A certificate covers its stated organization, ISMS scope, standard edition, and validity period; ISO does not audit organizations or issue certificates.

### Related terms

[Information security](<https://yellowcube.eu/glossary/information-security/>) · [Information security policy](<https://yellowcube.eu/glossary/information-security-policy/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Data governance](<https://yellowcube.eu/glossary/data-governance/>) · [NIST Cybersecurity Framework (CSF)](<https://yellowcube.eu/glossary/nist-cybersecurity-framework/>)

### Sources

[ISO, ISO/IEC 27001:2022 — Information Security Management Systems](https://www.iso.org/standard/27001.html) · [ISO, ISO/IEC 27001:2022/Amd 1:2024 — Climate Action Changes](https://www.iso.org/standard/88435.html) · [ISO, Certification](https://committee.iso.org/certification.html)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

