ISO/IEC 27001 (information security management)
ISO/IEC 27001 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). An ISMS is a risk-based framework of policies, processes and controls that protects the confidentiality, integrity and availability of information. The current edition, ISO/IEC 27001:2022, follows the harmonised structure of management-system standards (context, leadership, planning, support, operation, performance evaluation, improvement) and references 93 controls in Annex A, grouped into organisational, people, physical and technological themes, with implementation guidance in ISO/IEC 27002:2022. Organisations certified against the 2013 edition had to transition by October 2025. Certification is granted by accredited bodies after audit and maintained through annual surveillance and three-yearly recertification.
Related standards extend the ISMS: ISO/IEC 27701 adds privacy information management requirements for controllers and processors, mapping to GDPR obligations; ISO/IEC 27017 and 27018 address cloud security and protection of personal data in public clouds; ISO 27799 applies 27002 to health informatics; ISO/IEC 27005 covers information security risk management; and ISO/IEC 42001 applies the same architecture to AI management. In France, the HDS certification for hosting of health data builds on ISO 27001.
ISO 27001 has no formal legal status under the GDPR, but certification is widely used as evidence of "appropriate technical and organisational measures" under Art. 32 security of processing and as a proxy for processor guarantees under Art. 28; the NIS2 Directive allows Member States to require or recognise certification, and the MDR cybersecurity expectations and AI Act Art. 15 robustness requirements map onto ISMS controls. Sponsors and CROs therefore routinely require ISO 27001 (or SOC 2 Type II) from EDC, eCOA, cloud and safety-database vendors in their vendor assessments, while remembering that certification scope matters: a certificate covering only a data centre says little about application security or the vendor's staff. iliomad holds ISO 27001, 27005 and 9001 certifications and applies the standard's risk methodology in its DPIAs.
