Skip to content
01 / Applicability 02 / Control focus 03 / VISIONCYBERX
VISIONCYBERX / GRCManagement standard · defined scope
ISMS
ISO/IEC 27001
International requirements for an information security management system.
Scope comes first.
The 2022 edition supports risk-based management of information security. A certificate, if pursued, relates to a defined organisation and scope.
What to map.
- Scope and risk treatment
- Statement of Applicability and controls
- Internal audit and improvement
Our approach.
We establish an auditable ISMS with clear owners and evidence tied to operational risk.
Interpretation
This overview is not a certification or legal determination. Verify the current official text and assess your entity, services, country and contractual obligations.