Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, individual lessons, and BMC Cyber Challenge activities.

International standardAdvanced

ISO/IEC 27001

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system.

Management-system focus

The standard is not merely a technical control list. It establishes governance, scope, leadership, risk assessment, treatment, resources, competence, operation, measurement, internal audit, management review, and improvement.

Risk treatment

Organizations identify information-security risk, choose treatment, determine necessary controls, document applicability, and preserve evidence that the management system operates.

Certification

Independent certification can provide assurance that the management system meets the standard within a defined scope. Certification does not mean that no security incident can occur.

Continuous improvement

Audits, monitoring, corrective action, changing risk, business change, and management review should drive ongoing improvement rather than one-time compliance.

Certification relevance

This subject appears in or supports the following certification bodies of knowledge:

ISC2 CISSPISACA CISM

Authoritative sources