The international standard for establishing, operating and continually improving an information security management system (ISMS).
How an organisation governs information security as a management system — context and scope, leadership, risk assessment and treatment, a set of controls, and the operating cadence that keeps them effective.
Certification is granted by an independent accredited certification body. Orvella prepares organisations for that audit — it does not issue certificates.