ISO 27001 is a world standard to manage information security. The quality standard was originally published jointly by International Standards Organization (ISO), thereafter by the International Electrotechnical Commission (IEC) in 2005 and then revised in 2013. It details requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS) – the aim of which is to assist organizations make the knowledge assets they hold safer. An update of the quality standard was published in 2017. Organizations that meet the standard’s requirements can prefer to be certified by an accredited certification body following successful completion of an audit.
ISO/IEC 27001:2013 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of data security risks tailored to the requirements of the organization. The requirements specified in ISO/IEC 27001:2013 are generic and are intended to be applicable to all or any organizations irrespective of size.