The ISO / IEC 27001 ( ISO 27001) standard collects descriptions of the world’s best practices in the field of information security management. ISO 27001 specifies requirements for an information security management system to demonstrate an organization’s ability to protect its information resources. This International Standard has been prepared as a model for the development, implementation, operation, monitoring, analysis, maintenance and improvement of an Information Security Management System (ISMS).
The official version of ISO 27001.
The standard is based on the Deming-Shewhart cycle approach.
This allows not only to build correctly, but also to maintain the relevance of processes and controls on an ongoing basis in a timely manner.