ISO 27001
The international standard for information security management systems; organisations can be certified against it by accredited bodies.
Certification shows an organisation runs a management system that identifies information security risks and treats them with controls; Annex A lists the reference controls (93 in the 2022 edition). The certificate’s scope matters, because it may cover only part of a company. Certificates run for three years, with surveillance audits in between.
Source: ISO/IEC 27001:2022 ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.