← All terms

ISO 27001

ISO/IEC 27001 is the international standard for information security management systems — and it makes security awareness a required, auditable control.

ISO/IEC 27001 is the leading international standard for information security management, published jointly by ISO and the IEC and most recently revised in 2022. It specifies the requirements for an information security management system (ISMS): a risk-driven framework of policies, processes, and controls through which an organization identifies its security risks and treats them systematically. Organizations can be independently audited and certified against the standard, which is why "ISO 27001 certified" appears in so many vendor security pages and procurement questionnaires — for many buyers it is the baseline evidence that a supplier takes security seriously.

How it works

The standard has two layers. Clauses 4–10 define the management system itself — leadership commitment, risk assessment, objectives, resourcing, monitoring, and continual improvement. Annex A then lists 93 reference controls (in the 2022 edition, organized into organizational, people, physical, and technological themes) that organizations select from based on their risk assessment, documenting the choices in a Statement of Applicability.

The human layer is explicitly in scope. Clause 7.3 requires that everyone working under the organization's control be aware of the security policy, their role in the ISMS, and the consequences of falling short. Annex A control 6.3 goes further, calling for information security awareness, education, and training that is relevant to each person's role and delivered on a recurring basis. An auditor will ask to see the program, its content, and evidence that people actually completed it.

How to defend and comply

Treat the awareness requirement as an opportunity rather than a checkbox: an auditor-ready program is also the one that actually reduces risk. That means role-based security awareness training with completion records, realistic testing of behavior through phishing simulations, and metrics showing the trend an ISMS's "continual improvement" clause expects. Certification pairs naturally with the EU's regulatory wave — our guide to NIS2's human-risk requirements shows how the directive's training obligations map onto the same program an ISO 27001 audit wants to see. The same evidence travels: a SOC 2 Type II auditor and a PCI DSS assessor ask for the same training records and behavioral metrics, so one well-run program answers all three.

Related terms

NIS2 DirectiveThe NIS2 Directive (EU 2022/2555) is the EU cybersecurity law for 18 critical sectors, mandating risk management, training and 24-hour incident reporting.PCI DSSPCI DSS is the security standard for organizations handling card payments. Requirement 12.6 makes ongoing security awareness training mandatory.SOC 2SOC 2 is an audit framework for how service organizations protect customer data. What the Trust Services Criteria cover and where the human layer fits.Cyber HygieneCyber hygiene is the set of routine practices — updates, strong authentication, least privilege, awareness — that keeps users and systems resistant to attack.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo