ISO 27001 (formally known as ISO/IEC 27001:2005) is a specification for an information security management system (ISMS). An ISMS is a framework of policies and processes that includes all lawful, physical and technical controls involved in an organization’s information risk management procedures.
ISO/IEC 27001:2005 covers all types of organizations (e.g. commercial enterprises, government agencies, not-for profit organizations). ISO/IEC 27001:2005 identify the necessities for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented Information Security Management System within the context of the organization's in general business risks. It identifies necessities for the implementation of safety controls customized to the requirements of individual organizations or parts thereof.
The ISO/IEC 27001:2005 is the latest management system standard to support makes sure information security. This leading-edge tool supports allow organizations to organize information security processes and document subsequent actions in a format that permits companies to implement security controls that can be customized to their specific business requirements.