Grok-Pedia

ISO-27001

ISO-27001

ISO-27001 is an international standard that outlines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This standard was developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) under the joint committee ISO/IEC JTC 1/SC 27.

History

Key Components

Benefits of ISO-27001 Certification

Implementation and Certification

The process to achieve ISO-27001 certification involves:

  1. Defining the ISMS scope.
  2. Conducting a risk assessment.
  3. Developing and implementing security policies and controls.
  4. Undergoing an internal audit.
  5. Management review.
  6. Certification audit by an accredited certification body.

For more detailed information or to view the standard itself, you can refer to:

Related Topics

Recently Created Pages