ISO 27001
Definition
An international standard specifying requirements for an information security management system (ISMS) to keep sensitive data secure.In-Depth Explanation
ISO/IEC 27001, jointly published by ISO and IEC, defines how an organization should establish, operate, monitor, and continually improve an ISMS using a risk-management process. Certification is granted by accredited bodies such as BSI or DNV and follows a three-year cycle with annual surveillance audits. It preserves the confidentiality, integrity, and availability of information. Vendors often pursue it alongside SOC 2, as the two frameworks overlap significantly.
Real-World Example
A cloud provider earns ISO 27001 certification from an accredited auditor to assure customers its security controls meet an international benchmark.