ISO/IEC 27001 is the leading international standard for information security management. Rather than prescribing a fixed checklist of controls, it requires an organisation to establish an Information Security Management System (ISMS) — a risk-based programme for identifying, treating, and continually improving the management of information-security risk.
The standard is built around a risk-assessment and risk-treatment cycle. The organisation defines its scope, assesses risks to its information assets, selects controls to treat those risks (referencing the Annex A control set), and documents its decisions in a Statement of Applicability. An accredited certification body then audits the ISMS and, if it conforms, issues a certificate that is maintained through surveillance audits.
Because ISO 27001 is globally recognised, certification is often the credential international customers and partners expect. It pairs naturally with SOC 2 — the two share substantial control overlap — so many organisations pursue both from a single, unified control set.
Comply automates this — see the ISO 27001 framework page.