ISO 27001 specifies requirements to identify, control, and reduce security risks within the organization. It provides control measures to protect the confidential information from unauthorized access regardless of its forms such as digital, paper-based, intellectual property, company secrets, data on devices and in the cloud as well as in hard copies.