Security · Published
ISO/IEC 27001
Information security management.
A risk-based management system for protecting information, choosing controls and showing that those controls remain effective.
At a glance
What this edition means.
Publication: 2022-10. Verified against the publisher record on 25 September 2026. A future revision can change the current status.
Practical application
Start with how work happens.
Define the information and systems in scope, assess risks, choose proportionate treatment, involve suppliers and test the response to incidents.
First four moves
- Identify critical information and ownership
- Assess realistic threats and consequences
- Document treatment decisions and controls
- Test, audit and improve the system
Evidence to examine
Look for working arrangements.
Information security scope
Check whether this is current, owned and used in decisions or delivery.
Risk assessment and treatment
Check whether this is current, owned and used in decisions or delivery.
Statement of applicability
Check whether this is current, owned and used in decisions or delivery.
Incident and supplier records
Check whether this is current, owned and used in decisions or delivery.
Connected improvement
Follow the work beyond the standard.
AI governance
Keep an inventory of AI uses, accountable owners, impact assessments and monitoring decisions.
Explore Improvement topicCybersecurity
Prioritise information assets, common attack paths, recovery capability and supplier exposure.
Explore Improvement topicRisk management
Describe uncertain events in operational terms and choose proportionate responses with owners and review dates.
Explore Improvement topicBusiness continuity
Identify priority services and dependencies, choose recovery options and rehearse disruption.
Explore Improvement topicSupplier management
Know which suppliers matter, define expectations, check performance and prepare alternatives.
ExploreSource and scope