Skip to content

Standard · ISO/IEC

Information security management systems

The established information security standard; AI STANDARD refers to it where AI use touches data security, access control and suppliers.

ISO/IEC 27001:2022

What is it?

ISO/IEC 27001 specifies requirements for an information security management system (ISMS). The 2022 edition organizes reference controls into organizational, people, physical and technological themes.

Why does it matter?

Much AI risk — data leakage, unauthorized access, cloud supplier risk — is information security risk. Organizations with an ISMS can extend it with AI controls.

Who needs it?

  • Security leaders
  • IT managers
  • 27001-certified organizations adopting AI

Key concepts

Confidentiality, integrity, availability

The core security objectives, equally valid for AI use.

Supplier security

Most AI tools are third-party cloud services and should be assessed like any supplier.

Access control

Company accounts, least privilege and periodic review.

Requirements

  • AI STANDARD covers only the parts relevant to secure AI use.

Implementation

  1. 01Add AI tools to the information asset register
  2. 02Classify data and set input rules
  3. 03Assess AI suppliers
  4. 04Awareness training on prompt injection and data leakage

Assessment

The “Security & Access” and “Privacy & Data” dimensions cover this area.

Training

See the Security track courses such as “Secure Use of AI” and “Data Leakage”.

Resources

This page is AI STANDARD's explanation and interpretation; it does not reproduce the official text. Obtain the full standard from its publisher.