ISO/IEC 27001 is the leading international standard for information security management. Published by ISO and IEC, it specifies requirements for implementing, maintaining and continually improving an Information Security Management System (ISMS).
What does it cover?
The standard organizes controls into 93 requirements grouped across four thematic domains: organizational controls, people controls, physical controls and technological controls.
Why does it matter?
ISO 27001 certification demonstrates to customers, partners and regulators that an organization manages security systematically. Many B2B contracts and public tenders require it as a baseline prerequisite.
ermine and ISO 27001
ermine includes the complete ISO 27001:2022 template with all 93 Annex A controls pre-configured, risk assessment workflows aligned with the standard, and automatic generation of the Statement of Applicability (SoA).