# What is ISO/IEC 27001? Also called ISO 27001. ISO/IEC 27001 is an international standard specifying requirements for an information security management system, a documented framework for identifying security risks and applying controls to treat them. Organizations can be certified against it by an accredited body following an audit, and certification is commonly requested in enterprise and international procurement. The standard is management system oriented rather than prescriptive about technology. It requires defined scope, leadership commitment, a risk assessment methodology, a risk treatment plan, measurable objectives, competence and awareness, internal audits, management review and continual improvement. The recurring theme is that decisions are documented and revisited on a cycle rather than made once. An annex lists reference controls spanning organizational, people, physical and technological themes, revised in the 2022 edition of the standard. Organizations select applicable controls based on their risk assessment and record the reasoning in a statement of applicability, including justification for anything excluded. That document is central to the audit, because it links each control back to an identified risk. Certification follows a defined lifecycle: an initial audit in stages covering documentation and then implementation, surveillance audits during the certification period, and recertification at the end of the cycle. Certificates name a specific scope, so the meaningful question when reviewing one is which systems, locations and services that scope actually covers, not merely whether a certificate exists. Related standards extend the family. ISO/IEC 27701 addresses privacy information management, and ISO/IEC 42001 specifies an artificial intelligence management system, applying similar governance structure to AI specific risks. Organizations already operating a 27001 system often add these as extensions rather than as separate programs. ## Key points - Specifies an information security management system, not a technology list - Risk assessment drives control selection and the statement of applicability - Certification is issued by accredited bodies with a defined audit cycle - Certificate scope matters more than the certificate's existence - ISO/IEC 42001 extends the approach to AI management systems ## In practice A software vendor entering European enterprise deals is asked for certification. They define scope covering their production platform and supporting corporate systems, run a risk assessment, select applicable annex controls, document exclusions with reasons, and operate the system long enough to produce audit evidence such as internal audit records and management review minutes. An accredited body then audits in stages before issuing a scoped certificate. ## Related terms - [SOC 2](/en/glossary/soc-2) - [AI Governance](/en/glossary/ai-governance) - [Audit Trail](/en/glossary/audit-trail) [Back to the AI Glossary](/en/glossary)