Security · Published

ISO/IEC 27001
Information security management.

A risk-based management system for protecting information, choosing controls and showing that those controls remain effective.

At a glance

What this edition means.

Current edition2022
Previous edition2013
AmendmentAmd 1:2024 (climate action)
Revision statusCurrent edition

Publication: 2022-10. Verified against the publisher record on 25 September 2026. A future revision can change the current status.

Practical application

Start with how work happens.

Define the information and systems in scope, assess risks, choose proportionate treatment, involve suppliers and test the response to incidents.

First four moves

  1. Identify critical information and ownership
  2. Assess realistic threats and consequences
  3. Document treatment decisions and controls
  4. Test, audit and improve the system

Evidence to examine

Look for working arrangements.

01

Information security scope

Check whether this is current, owned and used in decisions or delivery.

02

Risk assessment and treatment

Check whether this is current, owned and used in decisions or delivery.

03

Statement of applicability

Check whether this is current, owned and used in decisions or delivery.

04

Incident and supplier records

Check whether this is current, owned and used in decisions or delivery.

Next step

Use a tool to frame discussion.

Source and scope

Know what you are reading.