ISO 27001 — ISO/IEC 27001 Information Security Management

Definition

An international standard for managing information security, providing a framework for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

Context & Usage

ISO 27001 certification demonstrates a systematic approach to information security. Annex A lists 93 controls covering 4 themes: organizational, people, physical, and technological. Common certification scope: cloud services, IT outsourcing, financial services. Most multinational SaaS vendors maintain ISO 27001 certification.

Examples

  • Microsoft Azure ISO 27001 certification
  • AWS ISO 27001/27017/27018

Looking for ISO 27001 hardware?

Pro Disk Network stocks enterprise IT hardware spanning every category. Email sales@prodisknetwork.com with your requirements for a quote.

Part of

B2B Procurement & Industry Solutions Hub

View all 248 pages →

Net 30 terms, RFQ workflow, federal / K-12 / healthcare / MSP procurement — for buyers spending $50K+ annually.