ISO 27001

ISO 27001

ISO 27001 is an international standard for how a company systematically protects its information. Those who meet it can have this confirmed by independent auditors and thus demonstrate security to customers.

ISO 27001 is a globally valid set of rules for handling information within companies. It describes how an organization ensures that data is not lost, does not fall into the wrong hands, and is not secretly altered. The standard does not prescribe any specific software or specific technology. Instead, it requires an orderly process: identify risks, define measures, review, improve. It is published by two international standards organizations, which is why its correct name is ISO/IEC 27001. A company can have independent auditors certify that it complies with these requirements.

Why customers ask for the certificate

Anyone entrusting a provider with their data cannot personally inspect that provider’s server rooms and password policies. A certificate under ISO 27001 replaces this distrust with the judgment of a neutral auditor. It works similarly to a vehicle inspection sticker: not every buyer understands brakes, but everyone trusts the seal. That is why large corporations and government agencies often demand the certificate before even negotiating a contract.

For young tech companies, this is a concrete economic issue. Without a certificate, they are often eliminated from many tenders right at the preselection stage. That is why ISO 27001 projects frequently appear in financial reports when a company wants to break into business with major clients. Depending on the size of the company, certification costs several tens of thousands of euros and often takes half a year or longer.

An important distinction is often confused. ISO 27001 is not a law but voluntary. The General Data Protection Regulation, on the other hand, is binding law in the EU. A certificate does not release anyone from legal obligations, but it does help fulfill them properly.

The cycle of risks, measures, and review

At the core of the standard is what is known as an information security management system. This is not a piece of software but a fixed collection of rules, responsibilities, and documents. It begins with a risk analysis: What could go wrong, how likely is it, and how costly would the damage be? Only afterward does the company decide which protective measures it actually needs.

An annex with around ninety possible measures serves as a toolkit. These include technical things like encryption and access rights, but also organizational ones like training or rules for departing employees. The company must document in writing which measures it uses and which it omits. After that, a continuous cycle runs: implement, monitor, analyze failures, improve.

The actual certification is carried out by an external certification body. Its auditors review documents and interview employees on site. The certificate is valid for three years, with annual audits in between. A common misconception is that a certificate means nothing can go wrong. It only means that the company was able to demonstrate an orderly approach to handling risks.

ISO 27001 in cloud services and AI products

The standard is most commonly encountered on the websites of cloud providers. There, data centers are rented out over the internet, and almost all major providers openly list their certificates. Providers of AI services are now also advertising it, because corporate clients have sensitive texts and customer data processed there.

In everyday life, the logo can also be seen in software companies' offerings, in privacy notices, and in job postings for IT security. In news reports, ISO 27001 usually comes up in two situations. Either a company proudly announces a new certification. Or, after a hacking attack, the question arises as to why the certificate did not prevent the incident.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.