Standards & Compliance

ISO 27001

International standard for information security management systems

ISO 27001 is an international standard that defines requirements for an Information Security Management System (ISMS). ISO 27001 certification demonstrates that an organization has implemented best practices for information protection.

Standard Structure

  • Organization context (4)
  • Leadership (5)
  • Planning (6)
  • Support (7)
  • Operation (8)
  • Performance evaluation (9)
  • Improvement (10)

Annex A: 93 Controls

Grouped into 4 categories:

  • Organizational (37)
  • People (8)
  • Physical (14)
  • Technological (34)

Certification Benefits

  • Competitive advantage
  • Regulatory compliance
  • Reduced incident risks
  • Client and partner trust

External Links

Category

ISO 27001, PCI DSS, GDPR, SOC 2, regulatory requirements