ISO/IEC 27001 Information Security Management
ISO/IEC (International Organization for Standardization / International Electrotechnical Commission)
To give organizations of any size or sector a systematic, internationally recognized framework, an Information Security Management System (ISMS), for identifying, treating, and continually improving how they manage information security risk.
Any organization, globally and cross-industry. It's especially common as a vendor-assurance requirement in international business and government contracting outside the US, where SOC 2 is less universally recognized.
Current edition is ISO/IEC 27001:2022, with Amendment 1:2024 (climate action changes), revising the 2013 edition. It defines 93 Annex A controls across 4 themes. Organizations certified to the 2013 edition had until October 31, 2025 to transition.
ISO/IEC 27001:2022KloudSec, built by the team behind Toc Consulting
What you just read is a manual, one-time check. KloudSec runs this and 400+ more automated checks across 90+ AWS services, continuously, agentless, live in about 5 minutes.