THREAT-WATCH logo

THREAT‑WATCH

Glossary

ISO 27001

An international standard for information security management systems, and the most widely recognized security certification.

ISO 27001 defines requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). Certification is issued by an accredited external body after an audit and requires ongoing surveillance audits to maintain. In practice, ISO 27001-aligned controls also cover much of what NIS2 technically requires, which is why the two are often addressed together.