Cybersecurity definition
What is ISO 27001?
By Cyber Tool Stack Editorial TeamUpdated
Definition
An international standard, published by the International Organization for Standardization, for building and certifying a formal information security management system — the standard many enterprise customers outside the U.S. (and increasingly within it) require as proof of a vendor's security program, playing a similar role to SOC 2.
Where ISO 27001 fits in the security landscape
These beginner lessons use this term while explaining the surrounding security control.
Related cybersecurity terms
SOC 2An audit report, defined by the AICPA (the American Institute of CPAs) — SOC stands for System and Organization Controls — that evaluates a service organization's controls around security, availability, and related trust criteria. SOC 2 is the specific report enterprise SaaS customers most often require, as distinct from SOC 1's focus on financial reporting controls.GRCGovernance, Risk, and ComplianceThe combined discipline of setting policy (governance), identifying and managing what could go wrong (risk), and proving adherence to laws and standards (compliance) — usually the umbrella term for the programs and tools that manage all three together.