ISO 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS), specifying requirements for establishing, operating, and continually improving information security.
ISO/IEC 27001 provides a risk-based framework for managing information security. Rather than prescribing a fixed checklist, it requires an organization to identify its information security risks and select controls to treat them, drawing on the reference controls in Annex A.
Certification is granted by an accredited body following a two-stage audit and is maintained through periodic surveillance audits and a recertification cycle, typically every three years. Central to the standard is the Information Security Management System (ISMS) — the policies, procedures, and governance structure that operationalize security.
Many organizations pursue ISO 27001 alongside SOC 2 because the two share substantial control overlap. Cross-framework control mapping lets a single piece of evidence satisfy requirements in both, reducing duplicate work.
Related terms
- SOC 2SOC 2 is an auditing standard that evaluates how a service organization manages customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
- Control MappingControl mapping is the practice of linking a single control to the multiple framework requirements it satisfies, so that one piece of evidence can support several frameworks at once.
- Risk RegisterA risk register is a centralized record of an organization's identified risks, capturing their likelihood, impact, ownership, and treatment status.
- Audit ReadinessAudit readiness is the state of having controls implemented and evidence organized so that an organization can enter a compliance audit with confidence and minimal last-minute work.