International · ISO and IEC
ISO/IEC 27001

ISO/IEC 27001 Information Security Management

The international standard for information-security management systems (ISMS), certifiable by accredited certification bodies.

Status · ISO/IEC 27001:2022

What ISO/IEC 27001 actually is.

ISO/IEC 27001 specifies the requirements for an Information Security Management System - a risk-based, top-down approach to protecting information assets through policies, processes and controls. The 2022 revision streamlines the Annex A control set to 93 controls organised across four themes (organisational, people, physical, technological). Certification is widely used as procurement evidence in Australia and is commonly accepted as an "equivalent" for the CIRMP cyber hazard requirement.

Applies to

Any organisation pursuing a certifiable information-security management system. Widely adopted in financial services, SaaS, managed services and supply-chain-critical vendors.

Key requirements

The control areas the framework covers.

Summary of the control families and outcomes the framework drives. Always validate against the official publication for the authoritative wording.

  1. 01

    Context of the organisation

    Understand the organisation and the needs of interested parties; determine ISMS scope.

  2. 02

    Leadership

    Top-management commitment, policy and assignment of roles and responsibilities.

  3. 03

    Planning

    Risk assessment and risk-treatment planning against information-security objectives.

  4. 04

    Support and operation

    Resources, awareness, communication, documented information and operational control.

  5. 05

    Performance evaluation

    Monitoring, internal audit and management review of the ISMS.

  6. 06

    Improvement

    Nonconformity and corrective action; continual improvement.

  7. 07

    Annex A controls (93)

    Control set grouped into organisational, people, physical and technological themes.

Official source

Read it from the issuing body.

For anything with a regulator or certification body behind it, the authoritative text is what counts - not our summary.

ISO and IEC

ISO/IEC 27001 Information Security Management

iso.org/standard/27001

Content on this page is a plain-language summary for programme planning. It is not legal or regulatory advice, and it does not replace a current copy of the issuer's publication.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.