Skip to content
atlas

ISO 27000 series

Also known as: ISO/IEC 27000 family, ISO 27k

The family of international standards for information security, with ISO 27001 at its centre and guides built around it.

Draft - this entry has not been reviewed yet.

Formal

A set of ISO/IEC standards on information security management - ISO 27000 (shared terms and the big picture), ISO 27001 (requirements for an ISMS, the only one you can be certified against), ISO 27002 (guidance on controls), ISO 27005 (risk management) and many more for specific areas.

In plain English

Like the booklets that come with a new car - one lists what the car must meet to pass its inspection, and the others explain the brakes, the lights and the engine in detail.

In practice

A Danish payroll service building its ISMS uses ISO 27001 for what it must do, ISO 27002 for how to carry out each control, and ISO 27005 to shape its method for assessing risk.

Why it matters

The series gives a shared, worldwide language for security, so customers, auditors and authorities can compare organisations on the same terms.

Technical deep dive

The series is maintained by the joint ISO/IEC committee JTC 1/SC 27 (Information security, cybersecurity and privacy protection), and the distinction that matters most is between requirements standards, written with "shall" and usable for certification, and guidance standards, written with "should". ISO/IEC 27001 is the central requirements standard; ISO/IEC 27006 sets requirements for the bodies that certify against it; and since its 2025 edition ISO/IEC 27701 is a standalone, certifiable privacy information management system rather than an extension of 27001. ISO/IEC 27000 supplies the overview and vocabulary and is a normative reference of 27001, so terms such as "risk owner", "control" and "nonconformity" carry their 27000 meaning in an audit.

The guidance layer is large. ISO/IEC 27002 describes the controls, 27003 explains how to implement the ISMS clauses, 27004 covers monitoring, measurement and evaluation, 27005 covers information security risk management, and 27007 and 27008 guide auditors of the management system and of the controls respectively. Sector and topic documents build on the same control structure: 27017 for cloud services, 27018 for processors of personal data in public clouds, 27019 for the energy utility industry, 27011 for telecommunications and ISO 27799 for health informatics, alongside topic standards such as 27031 (ICT readiness for business continuity), the 27035 parts on incident management and the 27036 parts on supplier relationships.

The lineage explains the numbering. British Standard BS 7799 Part 1 (1995) became ISO/IEC 17799 in 2000 and was renumbered ISO/IEC 27002 in 2007; BS 7799-2 became ISO/IEC 27001:2005. The 2013 revision moved 27001 onto the common structure for ISO management system standards, and the 2022 revision reorganised the controls into four themes, followed by a 2024 amendment adding climate change to the context clauses.

Common misconceptions: there is no such thing as being "ISO 27000 certified", and 27002 cannot be certified against; extensions such as 27017 and 27018 are normally assessed as additions to a 27001 certificate rather than as certificates of their own. The documents are copyrighted and sold by ISO and national bodies, which is one reason freely available frameworks such as the NIST CSF and the CIS Controls are often used alongside them. When comparing the two worlds, the NIST CSF lists ISO/IEC 27001 controls among its informative references, so the frameworks can be mapped rather than chosen between.

What to learn first

Everything this builds on, foundations first.

  1. Cyber and information security
  2. →ISO 27000 series

Relationships

Sources & further reading

Standards & official texts

  • ISO/IEC 27000:2018 - Overview and vocabulary

Course material

  • Cyber Security Fast Track - Kursuskompendium, Modul 1

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.