The standard *provides the description of control objectives that should be met*, and then the audit or assessment is designed to ensure that the organization properly implemented controls to meet those objectives. One common framework for conducting audits and assessments is the **Control Objectives for Information and related Technologies** ([[Control Objectives for Information and related Technologies|COBIT]]). The International Organization for Standardization ([[Organization for Standardization|ISO]]) also publishes a set of standards related to information security. [[ISO 27001]] describes a standard approach for *setting up an information security management system*, while ISO 27002 goes into more detail on the specifics of information security controls. These internationally recognised standards are widely used within the security field, and organisations may choose to become officially certified as compliant with ISO 27001.