ISO 27001 provides a framework that helps to establish, operate, maintain and continually improve an information security management system. The standard helps to improve processes so that organisations can operate more securely. There are ten management system clauses included in the standard, which are: scope, normative references, terms and definitions, context, leadership, planning and risk management, support, operations, performance evaluation, and improvement. There are also more than 100 information security controls included in the standard. Not all of the controls need to be implemented, but a risk assessment can determine which ones are most appropriate.
The control sets in ISO 27001 include areas such as information security policies, cryptography, operations security, and communications security. There are 18 sets of controls in total, covering a range of topics.