Compliance & regulation
The family of international standards for information security, with ISO 27001 at its centre and guides built around it.
Formal
A set of ISO/IEC standards on information security management - ISO 27000 (shared terms and the big picture), ISO 27001 (requirements for an ISMS, the only one you can be certified against), ISO 27002 (guidance on controls), ISO 27005 (risk management) and many more for specific areas.
In plain English
Like the booklets that come with a new car - one lists what the car must meet to pass its inspection, and the others explain the brakes, the lights and the engine in detail.
In practice
A Danish payroll service building its ISMS uses ISO 27001 for what it must do, ISO 27002 for how to carry out each control, and ISO 27005 to shape its method for assessing risk.
Why it matters
The series gives a shared, worldwide language for security, so customers, auditors and authorities can compare organisations on the same terms.