What it means
ISO/IEC 27001 certifies the organisation and its processes, not a specific device. For IoT companies it is most relevant to the cloud service, the mobile app backend and internal development practices, and it is frequently demanded in B2B procurement.
Applies to
- Cloud platforms and app backends
- Companies operating customer data at scale
- Vendors responding to enterprise security questionnaires
What it does not cover
- Device level security requirements
- Privacy law compliance, which ISO 27701 addresses
- Product certification of any kind
Verification checklist
- Define the scope and statement of applicability
- Assess risks and select controls
- Operate the management system with evidence
- Complete stage 1 and stage 2 audits and maintain surveillance audits