ISO/IEC 27001
ISO/IEC 27001 is an internationally recognized standard that sets out requirements for an information security management system (ISMS)—the policies, processes, and controls an organization uses to manage its information security risks. It is a voluntary standard rather than a law, though organizations may adopt it to demonstrate a structured approach to protecting information. Organizations can pursue independent certification against it, but doing so is optional unless required by contract or another obligation.
ISO/IEC 27001 is a jointly published international standard specifying requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) within the context of an organization. It defines a risk-based framework for bringing information security under explicit management control, encompassing management responsibilities, risk assessment and treatment, and the selection of applicable controls. It is a voluntary, certifiable standard—distinct from binding regulation—and conformity may be verified through third-party certification by an accredited body; certification attests to the ISMS meeting the standard's requirements at the time of audit and is not equivalent to legal compliance. The standard is periodically revised (the current revision commonly cited is the 2022 edition, superseding the 2013 edition), and readers should confirm the applicable version and requirements against the current official ISO text, as details of the standard and associated certification schemes change over time.
Why it matters
Information security risk is pervasive and difficult to manage consistently without a structured, repeatable approach. ISO/IEC 27001 matters because it provides an internationally recognized framework for bringing information security under explicit management control, rather than treating security as a collection of ad hoc technical measures. By defining requirements for an information security management system (ISMS), the standard gives organizations a common reference point for establishing, implementing, maintaining, and continually improving how they identify and treat information security risks.
As the world's best-known standard for information security management systems, ISO/IEC 27001 also carries significant weight in commercial and contractual settings. Organizations frequently ask vendors, service providers, and partners to demonstrate a mature security posture, and certification against the standard by an accredited third party offers a widely understood signal that an ISMS meets the standard's requirements at the time of audit. This can streamline procurement, due diligence, and supply-chain assurance where security expectations must be evidenced.
It is important to keep the standard's role in perspective. ISO/IEC 27001 is voluntary and certifiable—it is not a law, and certification is not equivalent to legal compliance. An organization may adopt it to demonstrate a disciplined approach to security, but obligations under specific regulations remain separate and must be assessed independently. Where certification is pursued, it attests to conformity at a point in time, not to permanent or absolute security.
Who it's relevant to
Inside ISO/IEC 27001
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27001.

