What is ISO/IEC 27001?
The international standard for an information security management system (ISMS): a structured way to manage security risks, backed by independent certification.
How it works
ISO/IEC 27001 sets requirements for establishing, running and continually improving an ISMS. Organisations assess their risks and choose controls, typically from Annex A, which in the 2022 version lists 93 controls in four themes: organisational, people, physical and technological.
Certification is issued by an accredited certification body after a two-stage audit, followed by surveillance audits and recertification every three years.
Key points
- A management system, not just a checklist
- 2022 version: 93 Annex A controls in four themes
- Certified by accredited bodies
- Three-year cycle with annual surveillance audits
Common questions
How long does certification take?
For an organisation starting from scratch, typically several months to a year, depending on size and maturity.
Can Touchpoint certify us?
No. We prepare and audit internally; an accredited certification body issues the certificate.
Talk to someone who does this every day
Questions about ISO 27001? Our team will give you a straight answer.