ISO 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive company information through risk assessment, security controls, and continuous improvement. Certification demonstrates that an organization meets globally recognized information security benchmarks.
Why It Matters
ISO 27001 is the most widely adopted information security standard globally. It requires organizations to identify information security risks, implement controls to address them, and maintain a management system that ensures continuous effectiveness.
The standard's Annex A contains 93 controls across organizational, people, physical, and technological domains. For AI agent governance, the relevant controls include access management (A.5.15-5.18), logging and monitoring (A.8.15-8.16), and secure development (A.8.25-8.31).
Organizations already certified to ISO 27001 have the management system infrastructure that agent governance extends. The gap is that ISO 27001's access controls assume human actors. Adding agent-specific policies, session-scoped permissions, and tool-call-level audit trails fills that gap without rebuilding the ISMS from scratch.