ISO 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines requirements for how an organization identifies risks, selects and operates controls, and continuously improves them. Certification is issued by accredited audit bodies after a stage 1 (documentation) and stage 2 (implementation) audit.
Unlike point-in-time attestations, ISO 27001 is a management system: it requires regular risk assessments, internal audits, management review, and corrective action. Surveillance audits happen annually, with full recertification every three years.
For cloud customers, an ISO 27001 certificate tells you a provider has a systematic security process — but not which controls protect your specific workload. Combine it with the statement of applicability, which lists exactly which of the standard's control categories the provider has implemented and any exclusions.
Edits go through a quick editor review.
Comments (0)
No comments yet. Start the discussion below.
Leave a comment
Sign in to comment