Skip to main content
Back to Glossary
Management Systems

ISO/IEC 27001

The international standard specifying requirements for an Information Security Management System (ISMS), widely required by enterprise colocation and cloud customers as a condition of contract.

Full Definition

ISO/IEC 27001 is published jointly by ISO and IEC. The 2022 edition defines 93 controls across four themes (Organisational, People, Physical, Technological) and requires organisations to establish, implement, maintain, and continually improve an Information Security Management System (ISMS). Certification is granted by accredited third-party auditors following a two-stage audit.

For datacentre operators, ISO 27001 addresses physical security (access control, CCTV, visitor management), logical security (network segmentation, access management), incident response, business continuity, and supplier management. In the European market, ISO 27001 is more commonly required than SOC 2 Type II in enterprise procurement — both may be mandated simultaneously. Certification is a commercial prerequisite for many colocation contracts and is mandatory in regulated sectors (financial services, healthcare, government).

Also Known As

ISO 27001ISO/IEC 27001:2022ISMS certification

Source Reference

ISO/IEC 27001:2022 — Information Security Management Systems: Requirements

Related Terms