Guide · ISO 27001

What is ISO 27001?

ISO/IEC 27001 is the international standard for information security. Here's what it is and how you get certified.

The short answer

ISO 27001 certifies that you operate an Information Security Management System (ISMS) — a documented, risk-driven program for protecting information — to an internationally recognized standard, verified by an accredited certification body.

What's an ISMS?

An ISMS is the set of policies, processes and controls that manage your information-security risk, plus the governance to keep improving it. ISO 27001 defines what a good one looks like.

Key artifacts

  • A defined scope and leadership commitment.
  • A risk assessment and treatment plan.
  • A Statement of Applicability (SoA) over the Annex A controls.
  • Internal audits and management review.

How certification works

An accredited body runs a Stage 1 (documentation) and Stage 2 (implementation) audit; passing earns a certificate, kept valid by annual surveillance. See the full process.

ISO 27001 vs SOC 2ISO 27001 is a globally recognized certification; SOC 2 is a US-centric attestation. Many companies do both — and the evidence overlaps heavily.

General explainer, not audit advice. ISO 27001 certification is issued by an accredited certification body, not by Vallorix.

See Vallorix on your own infrastructure

Continuous evidence, auditor-ready reports, and controls that stay in your boundary.

Get a demo →
V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect