Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

ISO/IEC 27001

ISO/IEC 27001 is the international standard for an information security management system (ISMS) — a risk-based, auditable framework of policies, controls, and continual-improvement processes for protecting information. Organizations are certified to it by accredited third parties, making it one of the two most widely-requested security assurances worldwide (alongside SOC 2). Its companion, ISO/IEC 27002, provides the detailed control catalog. The current edition is ISO/IEC 27001:2022.

ISO/IEC 27001 is the international benchmark for running an information security program as a system rather than a checklist — a certifiable management framework of risk assessment, controls, and continual improvement. Where SOC 2 produces an auditor’s report, ISO 27001 produces a certificate from an accredited body, and between them they cover most of what a security-conscious buyer asks for.

  • A management system, not a control list - It certifies that an organization runs security as a governed process; ISO 27002 supplies the control catalog it draws from.
  • Third-party certified - An accredited registrar audits and issues the certificate, refreshed on a surveillance cycle.
  • The global counterpart to SOC 2 - Non-US buyers tend to ask for ISO 27001; US buyers ask for SOC 2; serious vendors hold both.

ISO 27001 shows up throughout the trust-center posture of the payments and healthcare providers I score, and I catalogue it for the same reason I catalogue SOC 2 and HITRUST: it is real, and it is not the same thing as an agent-legible API. A certificate reassures a procurement team; it does not publish scopes, examples, idempotency, or consent. Keeping that distinction sharp is most of the point of the Kin Score.

Referenced in API Evangelist papers

This standard shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this standard in the context of a real sector.

The State of US Healthcare APIs

ISO 27001 is a recurring trust-center certification across the health-data platforms.