ISO/IEC 27001:2022
Information Security Management System
For organisations that process data, access customer systems or provide cloud services.
ClassManagement system standard
Edition2022
What is this standard?
Specifies information security management system requirements. Applicable to organisations of all sectors and sizes; data processing and information assets are stronger triggers than the sector itself.
Who is it for?
Any data-processing sector: software, cloud, finance, healthcare, e-commerce, contact centres, public sector and B2B services.
What triggers an assessment?
- Personal or commercial data is processed.
- Access to customer systems or a cloud service is provided.
- A cyber security or tender requirement is imposed.
What does it not replace?
- "We use computers" is not sufficient; data type, responsibility and information asset scope are questioned.
- It does not substitute for KVKK or GDPR compliance.
Official source
Last verified:
This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.