Skip to content
CyberNIS2

Glossary

ISO 27001

The leading international standard for setting up an Information Security Management System (ISMS), often used as a compliance framework for NIS 2.

ISO 27001 is an international standard that defines the requirements for establishing, maintaining and continuously improving an Information Security Management System (ISMS). Published by ISO (the International Organization for Standardization) and the IEC, it is the global benchmark for cybersecurity governance.

What the standard covers

ISO 27001 is built on a risk-based approach and notably requires:

  • Identifying and assessing information security risks.
  • Implementing security measures (technical, organisational, physical) proportionate to those risks.
  • A continuous improvement process (the PDCA cycle: Plan-Do-Check-Act).
  • Management involvement in security governance.
  • Regular internal and external audits to verify compliance.

ISO 27001 is not a legal requirement of NIS 2, but it is one of the most widely used frameworks for structuring a compliance programme:

  • The measures required by NIS 2 (risk management, business continuity, incident notification) overlap heavily with ISO 27001's requirements.
  • An organisation already ISO 27001 certified has a solid, documented basis to demonstrate compliance to competent authorities (ANSSI).
  • The standard makes it easier to trace and prove compliance, a key point during an inspection.

Certification

ISO 27001 certification is issued by an accredited body following an external audit verifying that the organisation's ISMS meets the standard's requirements. It is generally valid for 3 years, with annual surveillance audits.