Data Rooms Providers Find a data room
VDR glossary · Compliance and privacy

What is ISO 27001?

Definition

ISO 27001: An international standard for information security management systems; certification shows an independent auditor has checked that a provider runs a documented, risk-based security program.

How it works in a data room

ISO/IEC 27001 requires an organization to identify information security risks, choose controls to treat them, and review the whole system on a regular cycle. An accredited certification body audits the provider, issues a certificate with a defined scope, and returns for surveillance audits during the three-year cycle. For a data room, the scope should cover the platform, the hosting environment and the staff who operate it, not just a head office.

Why it matters in a deal

Procurement and IT teams at banks, law firms and large companies often treat certification as a minimum before any confidential material is uploaded. It gives assurance that controls such as access management, encryption, disaster recovery and penetration testing are written down and checked, rather than promised. When reviewing a provider, ask for the certificate, confirm its scope and expiry date, and check which accredited body issued it. Our methodology treats verified certifications as part of the security score, and the provider directory lists them.

Example

A pension fund in the Netherlands will not let its deal team use any vendor without current certification. During selection one provider shows a certificate covering only its sales office, while another’s scope names the platform and its data centers. The fund’s security team approves the second one in two days and asks the first for a scope statement it cannot provide in time.

Related terms