ISO/IEC 27001

ISO/IEC 27001:2022

Information Security Management Systems

A risk-based management system for protecting the confidentiality, integrity and availability of information.

ISO/IEC 27001:2022 service visual

Who this standard can apply to

IT and software companies
Educational institutions with digital records
Financial and professional services
Cloud, data-center and managed-service providers
Organizations handling confidential or personal information

Typical areas reviewed

Information-security risk assessment
Security policies and controls
Access, asset and supplier management
Incident and continuity controls
Monitoring, audit and improvement

Certification pathway

Application & Scope

Confirm the organization, sites, activities, requested standard and intended certification scope.

Document Review

Review relevant policies, procedures, records, objectives and management-system evidence.

Assessment / Audit

Evaluate implementation and objective evidence against the applicable requirements and approved arrangement.

Findings & Corrective Action

Where findings are identified, corrective action and supporting evidence are reviewed before closure.

Decision & Status

A defined decision is recorded with scope, validity and any applicable conditions or limitations.

Surveillance & Renewal

Ongoing status, surveillance and renewal requirements are managed according to the applicable certification arrangement.

Scope & Transparency

Certification, where offered, applies only to the defined management-system scope and responsible certification arrangement. It does not mean that ISO itself has certified or endorsed the organization.