Are you interested in the Interactive Course service ?
To buy it, choose the Personalized Offer on the right and select this option!
NF EN ISO/IEC 27001
- Free consultation sponsored by ANS (Digital Health Agency)
Information security, cybersecurity and privacy protection - Information security management systems - Requirements
This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.
Collections
Publication date
Number of pages
Reference
ICS Codes
Classification index
Print number
International kinship
European kinship
This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.
ISO/IEC 27001:2013 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in ISO/IEC 27001:2013 are generic and are intended to be applicable to all organizations, regardless of type, size or nature.
-
1 Domaine d'application
-
2 Références normatives
-
3 Termes et définitions
-
4 Contexte de l'organisation
-
5 Leadership
-
6 Planification
-
7 Supports
-
8 Fonctionnement
-
9 Évaluation de la performance
-
10 Amélioration
- Annexe A (normative) Référencement des mesures de sécurité de l'information
- Bibliographie
The Requirements department helps you quickly locate within the normative text:
- mandatory clauses to satisfy,
- non-essential but useful clauses to know, such as permissions and recommendations.
The identification of these types of clauses is based on the document “ISO / IEC Directives, Part 2 - Principles and rules of structure and drafting of ISO documents ”as well as on a constantly enriched list of verbal forms.
With Requirements, quickly access the main part of the normative text!

At a glance, you will be able to identify the additions, deletions or modifications to a text, table, figure and formula.

The Redlines + service is offered to you on the collection of French standards in force, in French language and in HTML and PDF format.
For an overview of the service, click on View a standard in redline format
COBAZ is the simple and effective solution to meet the normative needs related to your activity, in France and abroad.
Available by subscription, CObaz is THE modular solution to compose according to your needs today and tomorrow. Quickly discover CObaz!
Request your free, no-obligation live demo
I discover COBAZUnderstand the principles of the standard, apply them to; your business, raise awareness among your employees... So many imperatives that require time and resources.
To support you, AFNOR Éditions has designed the Interactive Paths to:
- Facilitate your understanding of the standard through; multimedia content
- Implement it more simply with concrete examples of application
- Better in efficiency; with handy, ready-to-use downloadable tools. employment
- Raising your employees awareness through a playful approach to the standard
Taking ownership of a standard has never been difficult. that easy!