Home / Insights / Glossary / ISO 27001

Glossary

ISO 27001

The international standard for an information security management system.

What it means

ISO/IEC 27001 specifies the requirements for establishing, operating and improving an information security management system, with a control set in Annex A. Certification is granted by an accredited body after audit.

The standard asks for a management system, not a control checklist — risk assessment, defined scope, management review and continual improvement. Organisations that treat Annex A as the whole task usually find the audit disagrees.

Where MyRISK fits

What we do about it

MyRISK is not a certification body and does not certify, audit or guarantee an outcome against ISO 27001. Where it helps is the evidence discipline underneath: controls and evidence held once and reused, and decisions recorded in a form a reviewer can follow.

MyRISK Core

Is this the thing you are actually trying to fix?

A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.