ISO/IEC 27001 is a certifiable standard for an information security management system, commonly called an ISMS.
An ISO 27001 program connects organizational scope, leadership, risk assessment, security objectives, controls, evidence, internal review, and continual improvement. Annex A provides a reference set of security controls, but organizations still need to decide which controls apply to their context and how they are implemented.
Certification is performed by an independent certification body. A policy pack or control list alone is not certification and does not prove that controls operate effectively.
Compare it with NIST CSF for SMBs or explore Framework-Pro for framework and control selection support.
