An information security management system implemented according to this standard is a tool for risk management, cyber-resilience and operational excellence. ISO/IEC 27001 promotes a holistic approach to information security: vetting people, policies and technology. ISO/IEC 27001 helps organizations become risk-aware and proactively identify and address weaknesses. With cyber-crime on the rise and new threats constantly emerging, it can seem difficult or even impossible to manage cyber-risks. The ISO/IEC 27001 standard provides companies of any size and from all sectors of activity with guidance for establishing, implementing, maintaining and continually improving an information security management system.Ĭonformity with ISO/IEC 27001 means that an organization or business has put in place a system to manage risks related to the security of data owned or handled by the company, and that this system respects all the best practices and principles enshrined in this International Standard. It defines requirements an ISMS must meet. ISO/IEC 27001 is the world's best-known standard for information security management systems (ISMS).