← ALL FRAMEWORKS

ISO/IEC 27001

Information Security

Issued by ISO/IEC

ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS), specifying requirements for establishing, implementing, maintaining, and continually improving a risk-based approach to protecting information assets. Annex A lists 93 controls — reorganized in the 2022 revision from 114 in the 2013 edition — grouped into organizational, people, physical, and technological categories. It's a certifiable standard: any company handling sensitive customer data, source code, or financial information can pursue certification through an accredited third-party auditor to demonstrate its security controls to customers, regulators, or partners. A 2024 amendment added a requirement to consider climate change as a relevant factor in the ISMS.

Get notified the moment ISO/IEC 27001 actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

No published updates yet

This framework hasn't had a confirmed update yet — check back after the next monitoring run.