Compliance & regulation
The international standard for running an information security management system that can be certified.
Formal
An international standard, current edition 2022, whose clauses 4-10 set the requirements for an information security management system - context, leadership, planning, support, operation, performance evaluation and improvement - with Annex A listing 93 controls to choose from.
In plain English
A set of house rules for running security as a daily routine rather than a one-off clean-up - written so that an outside inspector can check it is really followed.
In practice
Danish state bodies must follow ISO 27001, so the security lead at a ministry uses its clauses to set the scope, run the risk assessment, pick controls from Annex A and report maturity each year - without seeking a certificate.
Why it matters
Without a common measure every customer, auditor and authority would ask for security to be shown in a different way; ISO 27001 gives one structure that can be recognised, audited and mapped to laws such as NIS2.