Skip to content

Glossary · Australian Compliance

ISO 27001

The international standard for information security management systems, widely required in enterprise procurement and government supply chains.

Browse all definitions

In detail

ISO/IEC 27001 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). An accredited third party certification body grants certification after a formal audit. The standard requires documented risk assessment, a statement of applicability selecting from Annex A controls, management review and continuous improvement. The current version is ISO/IEC 27001:2022. Many organisations complement ISO 27001 with ISO 27017 (cloud controls) and ISO 27018 (PII in cloud).

Sources & further reading

Check the source, not just the summary

Apply the definition

Want to talk through how this applies to your business?

Start with the decision in front of you. We will help map the fit.

Straight answers · no pitch deck · no commitment