Skip to content
Glossary
Security

ISO 27001

The international standard for building and certifying an Information Security Management System (ISMS).

ISO/IEC 27001 is the leading international standard for information security management. Rather than prescribing a fixed checklist of controls, it requires an organisation to establish an Information Security Management System (ISMS) — a risk-based programme for identifying, treating, and continually improving the management of information-security risk.

The standard is built around a risk-assessment and risk-treatment cycle. The organisation defines its scope, assesses risks to its information assets, selects controls to treat those risks (referencing the Annex A control set), and documents its decisions in a Statement of Applicability. An accredited certification body then audits the ISMS and, if it conforms, issues a certificate that is maintained through surveillance audits.

Because ISO 27001 is globally recognised, certification is often the credential international customers and partners expect. It pairs naturally with SOC 2 — the two share substantial control overlap — so many organisations pursue both from a single, unified control set.

Comply automates this — see the ISO 27001 framework page.

See your compliance prove itself

Start free in minutes, or get a guided demo. No credit card, no per-seat surprises.

Free tier: 1 framework · 10 workers · 2 connectors. Upgrade only when you grow.