Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

ISO 27001 - Information Security Management System (ISMS)

ISO 27001 is the international ISMS standard for establishing, operating and continually improving information security.

Summary: ISO/IEC 27005 is the international standard for information security risk management. It defines the process for risk identification, assessment, treatment, and communication as part of an ISMS in accordance with ISO 27001. ISO 27005 is a methodological guide, not a certifiable standard, and describes how risks are assessed and treated in a structured manner.

Sources & References

  1. [1] ISO/IEC 27001:2022 - Information security management systems - International Organization for Standardization
  2. [2] BSI-Grundschutz und ISO 27001 - Bundesamt für Sicherheit in der Informationstechnik

Questions about this topic?

Our experts advise you free of charge and without obligation.

Free Consultation

About the Author

Oskar Braun
Oskar Braun

Head of Information Security Consulting

E-Mail

Dipl.-Math. (WWU Münster) and doctoral candidate at the Promotionskolleg NRW (Hochschule Rhein-Waal), researching phishing awareness, behavioral security and nudging in IT security. Responsible for building and maintaining ISMS, leads internal audits to ISO/IEC 27001:2022 and advises as an external information security officer (ISB) in KRITIS sectors. Lecturer for Communication Security at Hochschule Rhein-Waal and NIS2 training lead at isits AG.

ISO 27001 Lead Auditor (IRCA) ISB (TÜV) T.I.S.P. (TeleTrusT)
This article was last edited on 03/29/2026. Responsible: Oskar Braun, Head of Information Security Consulting at AWARE7 GmbH. License: CC BY 4.0 - free use with attribution: "AWARE7 GmbH, https://a7.de"

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen