ISO 27001
Ayrıca şöyle anılır ISO/IEC 27001, ISO 27001:2022, ISMS certification
ISO/IEC 27001 is an international standard that certifies not a product, but a process: whether an organization has a documented, risk-based system for managing information security, an Information Security Management System (ISMS), and actually runs it. Unlike SOC 2, which is an auditor's attestation report, ISO 27001 certification is closer to a formal pass/fail credential: an accredited certification body audits the organization against the standard's requirements, and if it passes, the organization receives a certificate valid for three years, subject to annual surveillance audits to keep it.
The standard's core requirement is that the organization define the scope of its ISMS, run a formal risk assessment, decide how to treat each identified risk, and then implement (or formally document why it's excluding) a defined set of controls. The current version, ISO/IEC 27001:2022, organizes those controls into 93 items across four themes: organizational, people, physical, and technological. A company can exclude controls that genuinely don't apply to it, as long as it documents why in a Statement of Applicability: the certification isn't "do all 93 things," it's "have a defensible, risk-based reason for what you do and don't do."
Who actually built this
ISO/IEC JTC 1/SC 27, the joint technical committee of the International Organization for Standardization and the International Electrotechnical Commission, develops and periodically revises the standard. Certification itself is performed by independent, accredited certification bodies, not by ISO, and not by the company seeking certification. None of this is Solidus's design.
Solidus today
No Solidus product has a published, documented Information Security Management System. No certification body has been engaged, no audit has started, and no certificate exists. This is grouped with SOC 2 and NIST iBeta as part of the same 2027 roadmap horizon for formal security certification, named directly rather than implied as further along than it is.
See also
SOC 2 answers a similar "can I trust this vendor's security" question through a different mechanism, an auditor's attestation rather than a management-system certification. NIST iBeta is the narrower certification specific to biometric liveness/anti-spoofing technology.
Nereden geliyor
Bunu başkası belirtti. Solidus bir araya getiriyor.
ISO/IEC 27001 is developed and maintained by ISO/IEC JTC 1/SC 27, the joint technical committee of the International Organization for Standardization and the International Electrotechnical Commission responsible for IT security standards. The current major revision is ISO/IEC 27001:2022. Certification against it is granted by accredited, independent certification bodies, never by ISO itself, and never by the company being certified.
Bunu nasıl doğrularsınız
Solidus bunu inşa etmedi. Girdi kavramı açıklıyor.
IAF CertSearch, the International Accreditation Forum's public registry of accredited management-system certificates, is where a genuine ISO 27001 certificate would be listed. Search it: Solidus will not appear, because no certification has been sought yet.