ISO 27001
ISO 27001 certifies that you have a management system for information security that meets the standard, not that your systems are secure.
It is about process: identifying risks, deciding controls, reviewing them, improving. That is genuinely valuable and it is a different claim from technical assurance. An organisation can hold the certificate and have a poorly configured estate, because the standard asks whether you manage the problem rather than how well you have solved it.
Checked against the primary source.
