← Legislation library

International

ISO 27001

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It defines requirements for establishing, maintaining, and continually improving information security, backed by the Annex A control set.

10 clauses

Clause 51

Leadership and commitment

Top management shall demonstrate leadership and commitment to the ISMS, ensuring the information security policy and objectives are established and compatible with the strategic direction.

Clause 81

Operational planning and control

The organisation shall plan, implement and control the processes needed to meet requirements and to implement the risk treatment actions.

Clause 92

Internal audit

The organisation shall conduct internal audits at planned intervals to confirm the ISMS conforms to requirements and is effectively implemented.

Clause 101

Continual improvement & nonconformity

The organisation shall continually improve the ISMS and take corrective action to address nonconformities.

Clause 500

A.5 Organizational controls

37 organizational controls covering policies, roles, threat intelligence, supplier and cloud security, incident management and business continuity.

Clause 600

A.6 People controls

8 people controls covering screening, terms of employment, awareness, disciplinary process and remote working.

Clause 612

Information security risk assessment

The organisation shall define and apply an information security risk assessment process to identify, analyse and evaluate risks.

Clause 613

Information security risk treatment & Statement of Applicability

The organisation shall define a risk treatment process, select controls, compare them against Annex A, and produce a Statement of Applicability.

Clause 700

A.7 Physical controls

14 physical controls covering secure areas, physical entry, equipment protection and secure disposal.

Clause 800

A.8 Technological controls

34 technological controls covering endpoint protection, cryptography, logging, network security, secure development and vulnerability management.

Turn ISO 27001 into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial