ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements
										Base data
									
									
										CESSDA ID
									
									
										crdr-4300
									
									
										
											Date of publication
										
										
											
												2022
																					
									
									
										
											Date added
										
										
											2022-11-24
										
									
									
										
											Last modified
										
										
											2024-12-26
										
									
									
										
											Resource type
										
										
											Webpage
										
									
								
											Description
										
										
											This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.
										
									
											Keyword tags
										
										
									
											Author(s)
										
										
											International Organization for Standardization
										
									
											Contributors
										
										
											
											
																								Other