What is it?
ISO/IEC 27001 specifies requirements for an information security management system (ISMS). The 2022 edition organizes reference controls into organizational, people, physical and technological themes.
Why does it matter?
Much AI risk — data leakage, unauthorized access, cloud supplier risk — is information security risk. Organizations with an ISMS can extend it with AI controls.
Who needs it?
- Security leaders
- IT managers
- 27001-certified organizations adopting AI
Key concepts
Confidentiality, integrity, availability
The core security objectives, equally valid for AI use.
Supplier security
Most AI tools are third-party cloud services and should be assessed like any supplier.
Access control
Company accounts, least privilege and periodic review.
Requirements
- AI STANDARD covers only the parts relevant to secure AI use.
Implementation
- 01Add AI tools to the information asset register
- 02Classify data and set input rules
- 03Assess AI suppliers
- 04Awareness training on prompt injection and data leakage
Assessment
The “Security & Access” and “Privacy & Data” dimensions cover this area.
Training
See the Security track courses such as “Secure Use of AI” and “Data Leakage”.
Resources
This page is AI STANDARD's explanation and interpretation; it does not reproduce the official text. Obtain the full standard from its publisher.