ISO 27001

ISO 27001 certifies that you have a management system for information security that meets the standard, not that your systems are secure.

It is about process: identifying risks, deciding controls, reviewing them, improving. That is genuinely valuable and it is a different claim from technical assurance. An organisation can hold the certificate and have a poorly configured estate, because the standard asks whether you manage the problem rather than how well you have solved it.

Checked against the primary source.

More on Frameworks & standards