ISO/IEC 27001
A management system standard. The certificate is proof you run the system, not that you are unbreachable.
ISO/IEC 27001 specifies an information security management system: scope, risk assessment, Statement of Applicability, internal audit, management review, improvement.
Annex A is a menu of controls. Treating it as a shopping list is how you get 114 tick-boxes and an open RDP server.
Useful when customers demand it. Insufficient alone for Australian government work, where ISM and Essential Eight still apply.
