ISO/IEC 27001 is the international standard for an information security management system (ISMS) — a risk-based, auditable framework of policies, controls, and continual-improvement processes for protecting information. Organizations are certified to it by accredited third parties, making it one of the two most widely-requested security assurances worldwide (alongside SOC 2). Its companion, ISO/IEC 27002, provides the detailed control catalog. The current edition is ISO/IEC 27001:2022.
ISO/IEC 27001
ISO/IEC 27001 is the international benchmark for running an information security program as a system rather than a checklist — a certifiable management framework of risk assessment, controls, and continual improvement. Where SOC 2 produces an auditor’s report, ISO 27001 produces a certificate from an accredited body, and between them they cover most of what a security-conscious buyer asks for.
- A management system, not a control list - It certifies that an organization runs security as a governed process; ISO 27002 supplies the control catalog it draws from.
- Third-party certified - An accredited registrar audits and issues the certificate, refreshed on a surveillance cycle.
- The global counterpart to SOC 2 - Non-US buyers tend to ask for ISO 27001; US buyers ask for SOC 2; serious vendors hold both.
ISO 27001 shows up throughout the trust-center posture of the payments and healthcare providers I score, and I catalogue it for the same reason I catalogue SOC 2 and HITRUST: it is real, and it is not the same thing as an agent-legible API. A certificate reassures a procurement team; it does not publish scopes, examples, idempotency, or consent. Keeping that distinction sharp is most of the point of the Kin Score.