{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/iso-27000-series","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/iso-27000-series/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/iso-27000-series/"},"term":{"en":"ISO 27000 series","da":"ISO 27000-serien"},"aka":{"en":["ISO/IEC 27000 family","ISO 27k"],"da":["ISO 27000-familien","ISO/IEC 27000-serien"]},"domain":["security"],"cluster":"compliance","layer":"governance","status":"current","era":2005,"summary":{"en":"The family of international standards for information security, with ISO 27001 at its centre and guides built around it.","da":"Familien af internationale standarder for informationssikkerhed med ISO 27001 i centrum og vejledninger bygget omkring den."},"body":{"formal":{"en":"A set of ISO/IEC standards on information security management - ISO 27000 (shared terms and the big picture), ISO 27001 (requirements for an ISMS, the only one you can be certified against), ISO 27002 (guidance on controls), ISO 27005 (risk management) and many more for specific areas.","da":"Et sæt ISO/IEC-standarder om styring af informationssikkerhed - ISO 27000 (begreber og overblik), ISO 27001 (krav til et ISMS, den eneste man kan certificeres efter), ISO 27002 (vejledning om kontroller), ISO 27005 (risikostyring) og mange flere for særlige områder."},"plain":{"en":"Like the booklets that come with a new car - one lists what the car must meet to pass its inspection, and the others explain the brakes, the lights and the engine in detail.","da":"Som hæfterne, der følger med en ny bil - ét fortæller, hvad bilen skal leve op til for at bestå synet, og de andre forklarer bremser, lys og motor i detaljer."},"inPractice":{"en":"A Danish payroll service building its ISMS uses ISO 27001 for what it must do, ISO 27002 for how to carry out each control, and ISO 27005 to shape its method for assessing risk.","da":"En dansk lønservicevirksomhed, der bygger sit ISMS, bruger ISO 27001 til, hvad den skal gøre, ISO 27002 til, hvordan hver kontrol gennemføres, og ISO 27005 til at forme sin metode til risikovurdering."},"whyItMatters":{"en":"The series gives a shared, worldwide language for security, so customers, auditors and authorities can compare organisations on the same terms.","da":"Serien giver et fælles, verdensomspændende sprog for sikkerhed, så kunder, auditorer og myndigheder kan sammenligne organisationer på samme grundlag."}},"deepDive":{"en":"The series is maintained by the joint ISO/IEC committee JTC 1/SC 27 (Information security, cybersecurity and privacy protection), and the distinction that matters most is between requirements standards, written with \"shall\" and usable for certification, and guidance standards, written with \"should\". ISO/IEC 27001 is the central requirements standard; ISO/IEC 27006 sets requirements for the bodies that certify against it; and since its 2025 edition ISO/IEC 27701 is a standalone, certifiable privacy information management system rather than an extension of 27001. ISO/IEC 27000 supplies the overview and vocabulary and is a normative reference of 27001, so terms such as \"risk owner\", \"control\" and \"nonconformity\" carry their 27000 meaning in an audit.\n\nThe guidance layer is large. ISO/IEC 27002 describes the controls, 27003 explains how to implement the ISMS clauses, 27004 covers monitoring, measurement and evaluation, 27005 covers information security risk management, and 27007 and 27008 guide auditors of the management system and of the controls respectively. Sector and topic documents build on the same control structure: 27017 for cloud services, 27018 for processors of personal data in public clouds, 27019 for the energy utility industry, 27011 for telecommunications and ISO 27799 for health informatics, alongside topic standards such as 27031 (ICT readiness for business continuity), the 27035 parts on incident management and the 27036 parts on supplier relationships.\n\nThe lineage explains the numbering. British Standard BS 7799 Part 1 (1995) became ISO/IEC 17799 in 2000 and was renumbered ISO/IEC 27002 in 2007; BS 7799-2 became ISO/IEC 27001:2005. The 2013 revision moved 27001 onto the common structure for ISO management system standards, and the 2022 revision reorganised the controls into four themes, followed by a 2024 amendment adding climate change to the context clauses.\n\nCommon misconceptions: there is no such thing as being \"ISO 27000 certified\", and 27002 cannot be certified against; extensions such as 27017 and 27018 are normally assessed as additions to a 27001 certificate rather than as certificates of their own. The documents are copyrighted and sold by ISO and national bodies, which is one reason freely available frameworks such as the NIST CSF and the CIS Controls are often used alongside them. When comparing the two worlds, the NIST CSF lists ISO/IEC 27001 controls among its informative references, so the frameworks can be mapped rather than chosen between.","da":"Serien vedligeholdes af den fælles ISO/IEC-komité JTC 1/SC 27 (informationssikkerhed, cybersikkerhed og beskyttelse af privatlivet), og den vigtigste sondring går mellem kravstandarder, formuleret med \"skal\" og brugbare til certificering, og vejledende standarder, formuleret med \"bør\". ISO/IEC 27001 er den centrale kravstandard; ISO/IEC 27006 stiller krav til de organer, der certificerer efter den; og siden 2025-udgaven er ISO/IEC 27701 et selvstændigt, certificerbart ledelsessystem for privatlivsbeskyttelse i stedet for en udvidelse af 27001. ISO/IEC 27000 leverer overblikket og begrebsapparatet og er normativ reference i 27001, så begreber som \"risikoejer\", \"kontrol\" og \"afvigelse\" har deres 27000-betydning under en audit.\n\nVejledningslaget er stort. ISO/IEC 27002 beskriver kontrollerne, 27003 forklarer, hvordan ISMS-afsnittene implementeres, 27004 dækker overvågning, måling og evaluering, 27005 dækker risikostyring for informationssikkerhed, og 27007 og 27008 vejleder auditorer af henholdsvis ledelsessystemet og kontrollerne. Sektor- og emnedokumenter bygger på den samme kontrolstruktur: 27017 for cloudtjenester, 27018 for databehandlere af personoplysninger i offentlige clouds, 27019 for energiforsyningen, 27011 for telesektoren og ISO 27799 for sundhedsinformatik, suppleret af emnestandarder som 27031 (IKT-parathed til driftskontinuitet), 27035-delene om hændelseshåndtering og 27036-delene om leverandørforhold.\n\nHistorikken forklarer nummereringen. Den britiske standard BS 7799 del 1 (1995) blev til ISO/IEC 17799 i 2000 og omdøbt til ISO/IEC 27002 i 2007; BS 7799-2 blev til ISO/IEC 27001:2005. Revisionen i 2013 flyttede 27001 over på den fælles struktur for ISO's ledelsessystemstandarder, og revisionen i 2022 omorganiserede kontrollerne i fire temaer, fulgt af et tillæg i 2024, der føjede klimaforandringer til afsnittene om kontekst.\n\nTypiske misforståelser: man kan ikke være \"ISO 27000-certificeret\", og man kan ikke certificeres efter 27002; udvidelser som 27017 og 27018 vurderes normalt som tillæg til et 27001-certifikat frem for som selvstændige certifikater. Dokumenterne er ophavsretligt beskyttede og sælges af ISO og de nationale standardiseringsorganer som Dansk Standard, hvilket er én grund til, at frit tilgængelige rammeværker som NIST CSF og CIS Controls ofte bruges ved siden af. Sammenligner man de to verdener, henviser NIST CSF til ISO/IEC 27001-kontroller blandt sine informative referencer, så rammeværkerne kan kobles sammen i stedet for at være et enten-eller."},"edges":[{"type":"requires","to":"security/cyber-and-information-security","confidence":"high","strength":"normal"},{"type":"kind-of","to":"security/security-framework","confidence":"high","strength":"normal"},{"type":"contrasts-with","to":"security/nist-csf","why":{"en":"The ISO series is a set of certifiable standards; the NIST framework is a free, voluntary guide without certification.","da":"ISO-serien er et sæt standarder, man kan certificeres efter; NIST-rammeværket er en gratis, frivillig vejledning uden certificering."},"confidence":"high","strength":"normal"}],"depth":1,"sources":[{"title":"Cyber Security Fast Track - Kursuskompendium, Modul 1","tier":"course-material"},{"title":"ISO/IEC 27000:2018 - Overview and vocabulary","tier":"standard"}],"draft":true}