Standard

    ISO/IEC 27001

    ISO/IEC 27001 Information Security Management

    ISO/IEC (International Organization for Standardization / International Electrotechnical Commission)

    Why It Exists

    To give organizations of any size or sector a systematic, internationally recognized framework, an Information Security Management System (ISMS), for identifying, treating, and continually improving how they manage information security risk.

    Who It's For

    Any organization, globally and cross-industry. It's especially common as a vendor-assurance requirement in international business and government contracting outside the US, where SOC 2 is less universally recognized.

    Current Status

    Current edition is ISO/IEC 27001:2022, with Amendment 1:2024 (climate action changes), revising the 2013 edition. It defines 93 Annex A controls across 4 themes. Organizations certified to the 2013 edition had until October 31, 2025 to transition.

    ISO/IEC 27001:2022

    Frequently Asked Questions

    KloudSec, built by the team behind Toc Consulting

    See ISO/IEC 27001 checked automatically, continuously

    What you just read is a manual, one-time check. KloudSec runs this and 400+ more automated checks across 90+ AWS services, continuously, agentless, live in about 5 minutes.

    Try KloudSec free