Drata Logo Dark (New)
  • Product
  • Resources
  • Alliances
  • Customers
  • Company
    Sign inGet Started
  • Sign in
  • Get Started
HomeCompliance GlossaryISO 27006

ISO 27006

ISO 27006 is an international standard that specifies requirements for the certification of information security management systems (ISMS).


It provides a framework for organizations to have their ISMS certified by a third-party certification body. ISO 27006 is intended to help organizations demonstrate the effectiveness of their information security management practices and gain recognition for their efforts.


To become certified, an organization must implement an ISMS that meets the requirements of ISO 27001 and be audited by a certification body that is accredited by a national accreditation body. The certification process typically involves several stages, including an initial assessment, a formal audit, and a surveillance audit, to ensure the organization meets the certification requirements.

Join the Thousands of Companies that Trust Drata

See All Case Studies
Wiz logo 2
Airbase
TaskRabbit Logo
BambooHR Logo
Clearbit Logo
Superhuman
Alteryx logo
Lemonade Logo
Notion Logo
Vercel Logo
Wordpress VIP
Calendly Logo

View Drata Glossary

Learn more about other compliance and cybersecurity concepts in our glossary.

Read More

Solutions

StartupMid-MarketEnterpriseDrata PlatformIntegrations
Frameworks
SOC 2ISO 27001HIPAAGDPRNIST AI Risk ManagementFedRAMPNIS 2Custom FrameworksAll Frameworks
Resources
BlogEventsWebinarsReportsSOC 2 HubISO 27001 HubProduct UpdatesCompliance GlossaryAPI Documentation
Company
CareersCustomersAuditorsPartnersPressContact UsLegal
Trust
Security and ComplianceTrust CenterSystem StatusAccessibility

Drata Logo Light

© 2025 Drata Inc. All rights reserved.

|Privacy Notice|Legal