ISO/IEC 27001:2022

ISO/IEC · Information security management systems SIGNET support: Compliance enablement — certifications as verifiable data

What it is

ISO/IEC 27001 is the international standard for information security management systems: the requirements an organisation must meet to establish, operate, and continually improve its management of information-security risk. Certification against it is the most widely recognised signal of security posture in commercial due diligence, and its 2022 revision is current.

The standard is maintained by ISO and IEC. Official reference →

How SIGNET supports it

ISO 27001 sits in SIGNET's compliance enablement tier — the honest framing for a management-system standard. SIGNET does not implement ISO 27001, and operating a SIGNET network confers no certification. What the standard does is make certification status portable, verifiable, and enforceable within a procurement process.

The canonical Credential object carries an ISO 27001 certification as a W3C Verifiable Credential — issuer, validity period, claims, and cryptographic proof — so a buyer verifies the certification itself rather than trusting a PDF. With selective disclosure, a supplier can prove it holds the certification without revealing the full certificate.

Enforcement is structural. Eligibility requirements are machine-readable Policy objects, and the worked examples include precisely this case: a sourcing event governed by an ISO 27001 eligibility policy, applied by a governed agent whose award decision records the policy it applied. Security certification stops being a checkbox in a questionnaire and becomes a verified input to an auditable decision.

Where it lives in the standard