An information and facts security management system that satisfies the requirements of ISO/IEC 27001 preserves the confidentiality, integrity and availability of data by making use of a chance management approach and provides self-assurance to interested parties that dangers are sufficiently managed