Glossary · Document types

ISO 27001

ISO 27001 is the international standard for information security management systems, and its certificate is the most commonly accepted proof that a supplier has independently audited security controls.

Full definition

ISO 27001 is defined as: ISO 27001 is the international standard for information security management systems, and its certificate is the most commonly accepted proof that a supplier has independently audited security controls.

ISO 27001 certification means a UKAS-accredited body has audited the supplier's controls against the standard's Annex A and confirmed they operate as documented. It is not a one-off exam - it requires surveillance audits and a full recertification every three years.

The certificate carries a scope statement. Check that the scope covers the actual service you are buying - a certificate that only covers head-office IT does not automatically apply to the supplier's SaaS product.

Questions and answers

Put it into practice

Manage iso 27001 in Credbase.

Credbase brings every supplier document into one workspace, tracks expiry dates for you and turns the whole set into a shareable evidence pack. Free to start, no card required.