International · ISO and IEC · ISO/IEC 27001

ISO/IEC 27001 Information Security Management

The international standard for information-security management systems (ISMS), certifiable by accredited certification bodies.

What it is

ISO/IEC 27001 specifies the requirements for an Information Security Management System - a risk-based, top-down approach to protecting information assets through policies, processes and controls. The 2022 revision streamlines the Annex A control set to 93 controls organised across four themes (organisational, people, physical, technological). Certification is widely used as procurement evidence in Australia and is commonly accepted as an "equivalent" for the CIRMP cyber hazard requirement.

Who it applies to

Any organisation pursuing a certifiable information-security management system. Widely adopted in financial services, SaaS, managed services and supply-chain-critical vendors.

Requirements

Context of the organisation

Understand the organisation and the needs of interested parties; determine ISMS scope.

Leadership

Top-management commitment, policy and assignment of roles and responsibilities.

Planning

Risk assessment and risk-treatment planning against information-security objectives.

Support and operation

Resources, awareness, communication, documented information and operational control.

Performance evaluation

Monitoring, internal audit and management review of the ISMS.

Improvement

Nonconformity and corrective action; continual improvement.

Annex A controls (93)

Control set grouped into organisational, people, physical and technological themes.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.