What is ISO 27001 in simple terms?
ISO 27001 is an international standard that describes how to manage information security in an organised way. In simple terms, it asks an organisation to work out what information it needs to protect, what could go wrong, and which controls will reduce those risks to an acceptable level, then to check regularly that the controls work. The result is called an information security management system, or ISMS. The standard covers people, processes, premises, and technology, not just IT systems. Any organisation can apply it, and those that want independent proof can be audited and certified by an accredited certification body, which is often requested by enterprise customers.
