Glossary

ISO 27001

ISO/IEC 27001 is the international standard for information security management systems (ISMS), specifying requirements for establishing, operating, and continually improving information security.

ISO/IEC 27001 provides a risk-based framework for managing information security. Rather than prescribing a fixed checklist, it requires an organization to identify its information security risks and select controls to treat them, drawing on the reference controls in Annex A.

Certification is granted by an accredited body following a two-stage audit and is maintained through periodic surveillance audits and a recertification cycle, typically every three years. Central to the standard is the Information Security Management System (ISMS) — the policies, procedures, and governance structure that operationalize security.

Many organizations pursue ISO 27001 alongside SOC 2 because the two share substantial control overlap. Cross-framework control mapping lets a single piece of evidence satisfy requirements in both, reducing duplicate work.

Related terms