Skip to main content

    We value your privacy

    We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Read our Cookie Policy to learn more.

    Skip to main content
    Back to Glossary
    framework
    2 min read

    ISO 27001

    ISO 27001 is an international standard for information security management systems (ISMS), providing a systematic approach to managing sensitive company information.

    ISO/IEC 27001 is the world's most recognized international standard for information security management. It provides a framework for establishing, implementing, maintaining, and continually improving an ISMS.

    The standard follows a risk-based approach: 1. Context: Understanding your organization and stakeholder needs 2. Leadership: Management commitment and security policy 3. Planning: Risk assessment and treatment plans 4. Support: Resources, competence, awareness, documentation 5. Operation: Implementing risk treatment and security controls 6. Performance evaluation: Monitoring, measurement, internal audits 7. Improvement: Corrective actions and continual improvement

    ISO 27001:2022 includes 93 controls across four themes: Organizational, People, Physical, and Technological.

    Certification process: - Stage 1: Documentation review - Stage 2: Implementation audit - Surveillance audits: Annual - Re-certification: Every 3 years

    Why It Matters

    ISO 27001 is the gold standard for information security worldwide. While SOC 2 dominates in North America, ISO 27001 is the de facto requirement for doing business internationally. Certification demonstrates a systematic, risk-based approach to security that satisfies regulators, enterprise buyers, and partners across all industries. The 3-year certification cycle also provides ongoing assurance compared to point-in-time assessments.

    Key Points

    International standard recognized globally
    Requires formal ISMS implementation
    Risk-based approach to security
    93 controls in the 2022 version
    3-year certification cycle with annual surveillance

    Applicable Compliance Frameworks

    Related Terms

    Related Articles

    Frequently Asked Questions

    What is the difference between ISO 27001 and ISO 27002?

    ISO 27001 is the certifiable standard. ISO 27002 provides detailed implementation guidance for the controls listed in ISO 27001 Annex A.

    How much does ISO 27001 certification cost?

    Total costs typically range from $20,000 to $100,000+ depending on organization size.

    Need Help with ISO 27001?

    Our experts can help you understand and implement the right controls for your organization.