ISO 27001 guidance
Back to ISO 27001
ISO 27001

ISO 27001 requirements

Trusted UK Auditors | Secure Compliance Tools | Expert Cyber Security Support

ISO 27001 requirements are built around a management system that is planned, supported, measured and improved.

Speak to NDC →
Requirements

ISO 27001 requirements

ISO 27001 requirements help organisations define responsibilities, controls, evidence, performance review and continual improvement for information security management systems.

STRUCTURE

The main ISO 27001 requirement areas.

ISO 27001 follows a management system approach. It asks organisations to understand context, define leadership responsibilities, plan controls, support people and resources, operate the system, evaluate performance and improve.

This summary is for orientation only. Organisations should use the official standard when implementing or auditing a management system.

  • Context and interested parties
  • Leadership and policy
  • Planning, risks and objectives
  • Support and documented information
  • Operational control
  • Performance evaluation and audit
  • Improvement and corrective action
EVIDENCE

Evidence proves the system is working.

ISO 27001 certification looks for evidence that controls are defined, used and improved. Records, audits, actions and management review outputs show whether the system is effective.

    Continue

    Explore more ISO 27001 guidance.