The international standard for an Information Security Management System (ISMS).
ISO/IEC 27001 is the international standard that specifies the requirements for an Information Security Management System (ISMS) — the management framework an organisation uses to identify, treat and monitor information-security risk. It is the most widely certifiable security-management standard, used as evidence of a serious security posture by regulators, auditors and customers.
The current edition (2022) reorganises Annex A into four control themes — organisational, people, physical and technological — with 93 controls in total, replacing the previous 14 categories / 114 controls structure.
Silbad's operational controls are aligned with ISO/IEC 27001 — the same standard the regulators of our customer institutions expect them to operate by.