What it is
ISO/IEC 27001 defines the requirements for establishing, implementing, maintaining, and continually improving an information security management system. It helps organizations manage risks related to the confidentiality, integrity, and availability of information.