What is ISO 27001?
ISO/IEC 27001 is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Published by ISO and IEC, it provides a systematic approach to managing sensitive company and customer information.
Key Components
- Risk assessment methodology for identifying and treating information security risks
- Annex A controls covering 93 security controls across four themes
- Plan-Do-Check-Act cycle for continuous improvement
- Statement of Applicability documenting control selection rationale
- Management commitment and resource allocation requirements
Benefits
ISO 27001 certification demonstrates to customers, partners, and regulators that an organization takes information security seriously and has implemented internationally recognized best practices.
Relationship to TISAX
The VDA ISA catalog used for TISAX assessments is based on ISO 27001 but includes automotive-specific requirements for prototype protection and data privacy. Organizations with ISO 27001 certification have a strong foundation for achieving TISAX compliance.
Back to Glossary