Skip to main content
ISO 27001 security for AI in production
← Back to journal
Security 10 min read

ISO 27001 security for AI in production

AI is not an exception to security: it is a new perimeter you must design and audit.

In this article

New attack surfaces

Prompt injection, exfiltration via tools, RAG corpus poisoning, MCP permission abuse. The model is not the only asset to protect.

Kodex framework

We align controls with ISO 27001 and OWASP practices for LLMs: AI asset inventory, data classification, least privilege, logging, and adversarial tests in the pipeline.

  • Data policy for prompts and tools
  • Environment and secrets segregation
  • Evidence for audits and committees

Evidence risk asks for

“We have a firewall” is not enough. You must show who can invoke which tool, what was logged, and how an incident is handled.

How to start

Inventory of AI cases, data matrix, ISO gap, remediation plan in sprints. Kodex implements or accompanies the diagnosis at the client’s pace.

Unlock the full article

Sign in with your Kodex community account to keep reading.

Ready to apply this in your organization?

Kodex executes with you — or start with resources. Same standard of rigor.

Tell us your goal

A short triage to qualify your request. In a few minutes we reach the right scope.

1

How would you like to collaborate with Kodex?

We open the right path — no unnecessary questions.

How would you like to collaborate with Kodex?

Tap a card to continue