ISO/IEC 27001 is the international standard for information security. Here's what it is and how you get certified.
The short answer
ISO 27001 certifies that you operate an Information Security Management System (ISMS) — a documented, risk-driven program for protecting information — to an internationally recognized standard, verified by an accredited certification body.
What's an ISMS?
An ISMS is the set of policies, processes and controls that manage your information-security risk, plus the governance to keep improving it. ISO 27001 defines what a good one looks like.
Key artifacts
- A defined scope and leadership commitment.
- A risk assessment and treatment plan.
- A Statement of Applicability (SoA) over the Annex A controls.
- Internal audits and management review.
How certification works
An accredited body runs a Stage 1 (documentation) and Stage 2 (implementation) audit; passing earns a certificate, kept valid by annual surveillance. See the full process.
General explainer, not audit advice. ISO 27001 certification is issued by an accredited certification body, not by Vallorix.