ISO/IEC 27001:2013 Preview

Information technology -- Security techniques -- Information security management systems -- Requirements

ISO/IEC 27001:2013 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in ISO/IEC 27001:2013 are generic and are intended to be applicable to all organizations, regardless of type, size or nature.


General information

  • Status :  Published
    Publication date : 2013-10
  • Edition : 2
    Number of pages : 23
  • :
    ISO/IEC JTC 1/SC 27
    IT Security techniques
  • 03.100.70
    Management systems
    35.030
    IT Security

Buy this standard

Format Language
PDF + Color PDF + ePub
PDF + ePub
PDF + ePub + Redline
Paper
PDF
  • CHF118

People also bought

  • ISO/IEC 27000:2018
    Information technology
    Security techniques
    Information security management systems
    Overview and vocabulary
  • ISO/IEC 27002:2013
    Information technology
    Security techniques
    Code of practice for information security controls
  • ISO/IEC 27005:2018
    Information technology
    Security techniques
    Information security risk management

Life cycle

A standard is reviewed every 5 years



Revisions / Corrigenda

You may be interested in:

Fingerprint login access on a smartphone.
By Clare Naden on
Reducing the risks of information security breaches with ISO/IEC 27005
In our hyper-connected, technology driven world, data breaches and cyber-attacks remain a significant threat to organizations, and a lack of awareness of the risks is often to blame. A newly revised standard will help.
By Barnaby Lewis on
ISO/IEC 27000 – key International Standard for information security revised
2018 may only have just begun, but it looks like a big year for information security. With questions being raised about the security of micro-processors, and major cyber security initiatives such as the EU’s General Data Protection Regulation brought into effect this year, a new edition of ISO/IEC 27000...
Network cables connected to switch
By Barnaby Lewis on
Information Security Management System auditors welcome ISO/IEC 27007 publication
To continue providing us with the products and services that we expect, businesses will handle increasingly large amounts of data. The security of this information is a major concern to consumers and companies alike fuelled by a number of high-profile cyberattacks.
By Clare Naden on
Use of ISO management system standards continues to rise
The number of valid certificates to ISO management system standards (MSS) rose 8 % in 2016 compared to 2015, according to latest figures of the ISO Survey.
By Maria Lazarte on
Are we safe in the Internet of Things?
Suppose a criminal were using your nanny cam to keep an eye on your house. Or your refrigerator sent out spam e-mails on your behalf to people you don’t even know. Now imagine someone hacked into your toaster and got access to your entire network. As smart products proliferate with the Internet of Things,...

Related pages

Got a question?

Check out our FAQs

Customer care
+41 22 749 08 88

Opening hours:
Monday to Friday - 09:00-12:00, 14:00-17:00 (UTC+1)

Keep up to date with ISO

Sign up to our newsletter for the latest news, views and product information

 Subscribe