This International Standard specifies the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS) within the context of an organization. It includes requirements for the assessment and treatment of information security risks tailored to an organization's risk appetite

The requirements set forth by the ISO/IEC 27001:2013 are generic and are intended to be applicable to all organizations, regardless of type, size or mission.