info@nexoprivacy.com +254 768200243 Mon - Sat | 24 Hours
Home Policies ISO/IEC 27001:2022 - Information Security
International · Global

ISO/IEC 27001:2022 - Information Security

The international standard for an Information Security Management System (ISMS) - increasingly demanded by enterprise buyers worldwide.

Quick facts

  • Code: ISO27001
  • Jurisdiction: Global
  • Region: International
  • Enforcement:
    Certification loss, contractual exposure, brand damage
  • Official source

ISO/IEC 27001:2022 is the foundation we recommend for any organisation that is serious about information security. Our ISMS engagements deliver Statement of Applicability, risk treatment plan, Annex A control implementation and audit support.


Key principles & obligations

Risk-based ISMS
93 Annex A controls
Continuous improvement
Top-management accountability
More in International

Related frameworks.

Global (Payment Card Industry)

PCI DSS v4.0

Mandatory technical and operational standard for any organisation that stores, processes or transmits cardholder data.

Read summary
Global

ISO/IEC 27701 - Privacy Information Management

Extends ISO/IEC 27001 with privacy-specific controls - the de-facto international certification for a Privacy Information Management System (PIMS).

Read summary
United States / Global

SOC 2 Type I & Type II

The AICPA Trust Services Criteria report demanded by enterprise buyers - a must-have for B2B SaaS.

Read summary