MarketplaceCybersecurityISO 27001:2013
CybersecurityStandard

ISO 27001:2013

ISO/IEC 27001:2013 - Information security management systems β€” Requirements

ISO/IEC 27001:2013 specifies the requirements for establishing, implementing, maintaining, and improving an information security management system tailored to organizational needs. It is applicable to organizations of any type, size, or nature.

Overview

ISO/IEC 27001:2013 is a global standard that outlines requirements for an Information Security Management System (ISMS). It provides a systematic approach for managing information security risks, emphasizing the development of policies, processes, roles, and controls. The standard is generic and suitable for any organization, ensuring flexibility in implementation. This version replaced the 2005 edition and was later superseded by ISO/IEC 27001:2022. It was formally withdrawn in October 2022. The standard also includes guidelines for risk assessment and treatment aligned with organizational needs.

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks β€” automatically.

Book your strategy call