ISO/IEC 27001:2022, including Amendment 1: Climate action changes
Information Security Management System
ISO/IEC 27001 (2022) is a management system standard: Information Security Management System. Specifies information security management system requirements. Applicable to organisations of all sectors and sizes; data processing and information assets are stronger triggers than the sector itself. It applies to any data-processing sector: software, cloud, finance, healthcare, e-commerce, contact centres, public sector and B2B services.
- Class
- Management system standard
- Edition
- 2022
- Related sectors
- 4
- Last verified
What is this standard?
Specifies information security management system requirements. Applicable to organisations of all sectors and sizes; data processing and information assets are stronger triggers than the sector itself.
What ISO/IEC 27001 does not replace
- "We use computers" is not sufficient; data type, responsibility and information asset scope are questioned.
- It does not substitute for KVKK or GDPR compliance.
Who is it for?
Any data-processing sector: software, cloud, finance, healthcare, e-commerce, contact centres, public sector and B2B services.
What triggers an assessment?
- Personal or commercial data is processed.
- Access to customer systems or a cloud service is provided.
- A cyber security or tender requirement is imposed.
Official source
Amendment source
- Amendment 1: Climate action changes ↗ — Last verified:
Last verified:
This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.