What is ISO 27001? Definition and explanations
ISO/IEC 27001 is the international standard that sets the requirements for an information security management system. It does not prescribe a list of technologies: it imposes a method — analyse risks, select justified controls, document them, measure them and improve them. An organisation can either conform to it or have its system certified by an accredited body.
In one sentence
ISO/IEC 27001 sets the requirements for an information security management system.