ISO/IEC 27001

< ISO

ISO/IEC 27001
StatusActive
First publishedOctober 2005
Latest version2022
Organization
CommitteeISO/IEC JTC 1/SC 27
SeriesISO/IEC 27000 family
PredecessorBS 7799
DomainInformation security
Websitewww.iso.org/standard/27001

ISO/IEC 27001 is an information security standard. It specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). Organizations with an ISMS that meet the standard's requirements can choose to have it certified by an accredited certification body following successful completion of an audit. There are also numerous recognized national variants of the standard.

It was originally published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) in 2005, with revisions in 2013 and 2022.