Back to glossary
Glossary
ISO 27001
An international standard for managing information security across an entire organisation, not just IT.
ISO 27001 is a broader, more formal standard than Cyber Essentials — it covers an organisation's whole information security management system, including policies, risk assessment processes, and continual improvement, not just a fixed checklist of technical controls. Certification requires an external audit and is typically pursued by larger organisations or those selling into sectors that require it.
Related terms
Got a question that's not in the glossary?
Ask us directly — no jargon, straight answers.
Get in touch