ISO 27001/27002
02 Jul 2026

ISO 27001/27002

Relevant Cybersecurity Publications

Description

Who is it intended for?

The ISO 27001 standard applies to any public or private organization, large or small, that wishes to implement information security management in a standardized manner.

What is it?

The UNE-EN ISO/IEC 27001:2017 standard is an international standard that establishes the requirements an Information Security Management System (ISMS) must meet to be certifiable. In effect as an international standard since 2005, this standard establishes:

The general requirements that must be met at the management system level so that security management is carried out using the Deming cycle or PDCA cycle (Plan-Do-Check-Act) and can be established, implemented, and continuously improved.

The specific requirements that must be met from an information security perspective, consisting of developing a process for analyzing and managing information security risks and, as a result of that process, applying a series of security controls that must be verified against the catalog of controls included as an annex to the standard itself.

In this way, the standard lays the groundwork for any organization to preserve the confidentiality, integrity, and availability of information, in accordance with its business interests and needs, through the application of a continuous information security risk management process.