Risk Management - Standard
ISO 27001
An international standard for how organisations manage information security
What's it for?
Gives organisations a recognised standard for managing and improving how they protect information.
For example…
A SaaS vendor shares its ISO 27001 certificate during due diligence to evidence a structured security programme.
A company pursuing ISO 27001 documents its security risks, controls and review process, then an independent auditor checks the management system.
Think of it like…
Kitchen hygiene rating: it does not cook the meals, but it signals that processes for safety are in place and inspected