ISO 27000
Information Security Management Systems - Overview and Vocabulary
ISO 27000:2018 at a glance
- Current edition
- ISO/IEC 27000:2018 - Information technology — Security techniques — Information security management systems — Overview and vocabulary
- Published
- 2018
- Status
- Published
- Type of standard
- Vocabulary
- Certifiable
- No — used for reference and implementation, not certification
- Previous edition
- ISO/IEC 27000:2016
- Official ISO page
- View ISO 27000:2018 on iso.org
- Last verified
Overview
The overview and vocabulary document for the ISO/IEC 27000 family. It explains how the ISMS standards fit together and defines the terms they use, and is available free of charge from ISO.
ISO/IEC 27000:2018, Information security management systems — Overview and vocabulary, is the entry point to the ISO/IEC 27000 family. It was published in 2018 and replaced ISO/IEC 27000:2016. It is developed by ISO/IEC JTC 1/SC 27, the joint subcommittee responsible for information security, cybersecurity and privacy protection.
It does two things. First, it gives an overview of information security management systems: what an ISMS is, why an organization would operate one, and the concepts of information security — confidentiality, integrity and availability of information — that the family is built on. Second, it provides the terms and definitions commonly used across the ISMS family, so that words such as control, risk, threat, vulnerability, information security incident and information security event carry the same meaning in every document.
The standard also maps the family. It describes the scope, role and function of the individual standards and their relationship to one another: the requirements standard (ISO/IEC 27001), the controls guidance (ISO/IEC 27002), implementation and risk guidance (ISO/IEC 27003, ISO/IEC 27005), measurement (ISO/IEC 27004), the requirements for certification bodies (ISO/IEC 27006 series), auditing guidance (ISO/IEC 27007), and the sector- and topic-specific documents such as cloud security controls and privacy information management. For anyone approaching the family for the first time, this map is the fastest way to work out which document answers which question.
The standard is explicit about its limits: the terms it defines cover commonly used terms in the ISMS family, do not cover every term used in every document in the family, and do not prevent individual standards from defining new terms for their own use.
ISO/IEC 27000 is not certifiable. It contains no requirements. Organizations certify to ISO/IEC 27001; ISO/IEC 27000 supplies the shared vocabulary and context that make ISO/IEC 27001 readable. Unusually among ISO standards, it is made available free of charge through ISO's publicly available standards service, which makes it a practical first read for anyone scoping an ISMS project.
Note that the 2018 edition still carries the older Information technology — Security techniques title prefix, whereas ISO/IEC 27001:2022 and ISO/IEC 27002:2022 use the current Information security, cybersecurity and privacy protection prefix. The vocabulary remains usable, but where the 2022 editions of ISO/IEC 27001 and ISO/IEC 27002 define or use terms directly, those documents take precedence for their own requirements and controls.
Purpose
To provide an overview of information security management systems and the ISO/IEC 27000 family of standards, and to define the terms and definitions commonly used across that family, so that the standards are understood and applied consistently.
Key Benefits
- Explains how the ISO/IEC 27000 family fits together and which standard to use for what
- Defines the shared vocabulary used across the ISMS standards
- Provides an accessible introduction to information security management system concepts
- Available free of charge, so it can be circulated widely inside an organization
- Reduces misinterpretation of terms during ISMS implementation and certification audits
- Useful as an orientation document for management and non-specialist stakeholders
- Supports consistent terminology in internal security policies and procedures
- Helps scoping decisions by clarifying the role of each standard in the family
Key Requirements
- Reference document only — ISO/IEC 27000 contains no auditable requirements
- Understand the concept of an information security management system and why organizations operate one
- Understand confidentiality, integrity and availability as the core information security properties
- Use the defined terms consistently across ISMS documentation
- Understand the distinction between information security events, incidents and nonconformities
- Understand the roles of ISO/IEC 27001, 27002, 27003, 27004, 27005 and the 27006 series
- Recognise the sector- and topic-specific standards in the family and when they apply
- Recognise that individual standards in the family may define additional terms for their own use
Who Needs This Standard?
Anyone starting work with the ISO/IEC 27000 family: information security managers and ISMS implementers, IT and risk professionals, internal auditors, consultants, and managers who need to understand what an ISMS is before committing to ISO/IEC 27001. It is also useful to procurement and legal teams interpreting information security clauses in contracts.
Where to get ISO 27000
The full text of ISO 27000 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 27000 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Send me the implementation checklist for ISO 27000, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Looking to get certified?
You cannot be certified to ISO 27000 — it is guidance, and no accredited scheme exists for it. The closest standard you can certify against is ISO 27001 (Information Security Management Systems).
If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with it. Free and no obligation.
In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).