Back to glossary
Glossary

ISO 27001

An international standard for managing information security across an entire organisation, not just IT.

ISO 27001 is a broader, more formal standard than Cyber Essentials — it covers an organisation's whole information security management system, including policies, risk assessment processes, and continual improvement, not just a fixed checklist of technical controls. Certification requires an external audit and is typically pursued by larger organisations or those selling into sectors that require it.

Got a question that's not in the glossary?

Ask us directly — no jargon, straight answers.

Get in touch