openskills.info
ISO/IEC 27001 logoCourse Preview

ISO/IEC 27001

ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines requirements for establishing, implementing, maintaining, and continually improving a management system that protects the confidentiality, integrity, and availability of information through a risk-based process.

itCybersecurity fundamentals and governance

ISO/IEC 27001

ISO/IEC 27001 is the international standard for information security management systems (ISMS). It specifies requirements an ISMS must meet to establish, implement, maintain, and continually improve a risk-based system that protects information. It is published jointly by ISO and the International Electrotechnical Commission (IEC), under the responsibility of ISO/IEC JTC 1/SC 27.

The standard applies to organizations of any size and from any sector. It does not tell you which safeguards to buy or install. Instead, it defines a management system that decides which information risks matter and how to treat them, then operates controls, reviews results, and improves. Conformity with ISO/IEC 27001 means an organization has put in place a system to manage risks related to the security of data it owns or handles, and that this system respects the principles and best practices the standard sets out.

The ISMS and its structure

An information security management system is the framework of policies, processes, procedures, roles, and controls an organization uses to manage information security. ISO/IEC 27001 organizes the requirements for that framework in ten clauses. Clauses 1 through 3 cover scope, normative references, and terms. Clauses 4 through 10 are the operational core:

  1. Context of the organization — determines the internal and external issues relevant to information security, the interested parties whose requirements matter, and the scope of the ISMS. Clause 4.4 requires establishing, implementing, maintaining, and continually improving the ISMS, including the processes needed and their interactions.
  2. Leadership — top management establishes the information security policy, assigns roles and responsibilities, and demonstrates commitment. Clause 5.1 includes a note that the term "business" can be interpreted broadly.
  3. Planning — the organization addresses risks and opportunities, sets information security objectives, and plans changes to the ISMS. Clause 6.3 requires that changes to the ISMS be carried out in a planned manner.
  4. Support — the organization provides the resources, competence, awareness, communication, and documented information the ISMS needs.
  5. Operation — the organization plans, implements, and controls the processes needed to meet information security requirements, including implementing the actions determined in Clause 6. Clause 8.1 requires establishing criteria for the processes and controlling them in accordance with those criteria.
  6. Performance evaluation — the organization monitors, measures, analyzes, and evaluates information security performance, conducts internal audits, and holds management reviews. Clause 9.2.2 requires an internal audit program; Clause 9.3 requires management review.
  7. Improvement — the organization continually improves the ISMS and handles nonconformities and corrective actions.

Risk-based management

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources