ISO 27001 is an information security management system standard. It specifies requirements for a security policy, what to do if the security of your company’s assets are breached, and how to do it. In short terms, it is a documentation of what needs to be done by an organization with regards to information security and why they need to be implemented. The standard was created by the International Organization for Standardization (ISO), which is the world’s largest developer of voluntary international standards.

https://iasiso-middleeast.com/JO/blog/iso-27001/