ISO 27001 is the international standard for information security management systems. Rather than prescribing technologies, it defines how an organisation decides what to protect and how to prove that the protection works.
It is risk-based by design. Controls follow from a risk assessment rather than being applied wholesale, and the Statement of Applicability records which ones apply and why — keeping the system proportionate to the business it serves.
Certification comes from an accredited body after a two-stage audit: a review of the ISMS documentation, then verification that it runs in practice. The certificate lasts three years, with annual surveillance audits in between.
In Europe it is the recognised baseline for NIS 2 risk-management measures and supports GDPR Article 32 obligations — and it increasingly arrives as a precondition in enterprise procurement.