top of page

ISO/IEC 27000

ISO/IEC 27000:2026 — Information security, cybersecurity and privacy protection — Information Security Management Systems — Overview

(sixth edition)

Abstract

“ISO/IEC 27000 explains the core concepts and principles behind information security management systems, or ISMS. It provides an overview of the ISO/IEC 27000 family of standards, including ISO/IEC 27001, and clarifies how these documents relate to each other. The standard helps organizations understand the foundations of information security management before selecting, implementing or working with more specific ISMS standards.”

[Source: ISO.org)

Introduction

What is an Information Security Management System? What's the point? What is it for and what is it intended to achieve?  How does it do that? What does it consist of?  What is it not


If questions of that nature puzzle you, this brief standard helps by explaining a 'management system', specifically a systematic way of managing information risks and information security controls.

Scope

ISO/IEC 27000 outlines the ISO27k 'family of standards':

  1. ISO/IEC 27001 - ISMS requirements 

  2. ISO/IEC 27002 - information security controls 

  3. ISO/IEC 27003 - ISMS guidance 

  4. ISO/IEC 27004 - ISMS metrics

  5. ISO/IEC 27005 - information security risk management

  6. ISO/IEC 27006-1 - ISMS certification

  7. ISO/IEC 27007 - ISMS auditing

  8. ISO/IEC TS 27008 - information security controls assessment

  9. ISO/IEC 27010 - inter-sector and inter-organizational communications

  10. ISO/IEC 27011 - information security controls for telecommunications organizations

  11. ISO/IEC 27013 - integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 (ITIL)

  12. ISO/IEC 27014 - governance of information security 

  13. ISO/IEC TR 27016 - organizational economics

  14. IISO/IEC 27017 - information security controls for cloud services

  15. ISO/IEC 27019 - information security controls for energy utilities

  16. ISO/IEC 27021 - ISMS professional competencies

  17. ISO/IEC TR 27022 - ISMS processes

  18. ISO/IEC 27028 - information security control attributes 


It also mentions:

Structure

The 11-page standard has just three main clauses:

  • 3: Terms and definitions - formally defines 12 key terms used in this standard, 7 of which are shortened definitions form other standards (without their notes) leaving 5 unique definitions.  [1½ pages]

  • 4: Concepts and principles - introduces information security, risk and security management, and management systems. [4 pages]

  • 5: Documents* related to ISMS including ISO/IEC 27001 - succinct descriptions (just a sentence or so) of each of the standards numbered 1 to 18 above. [3 pages]


* Note: within ISO/IEC 27000, the term 'documents' means ISO and ISO/IEC standards, specifically, not documents in general. The mandatory and discretionary ISMS documents noted in ISO/IEC 27001 and other ISO27k standards are not described here, although a few are mentioned (e.g. ISMS scope and risk treatment plan).

Status

The first edition was published in 2009.


It was updated in 2012, 2014, 2016, 2018 and ... wait for it ... 2026.


The previous 5th edition was released by ISO for free as an introduction and promotion of ISO27k. A request has been lodged with ISO to make the current 6th edition free as well.  Until that is approved and actioned, any copies of ISO/IEC 27000:2026 found loitering on the web are probably pirated.

Commentary

Due to an ISO policy decision, the current 2026 sixth edition dropped previous editions' extensive glossaries of dozens of ISO27k terms, leaving just a dozen actually used in this standard. However, the official definitions remain available online in ISO's Online Browsing Platform and IEC's Electropedia.  


Alternatively, the Cybersecurity Hyperglossary defines well over 5,000 terms in plain English, as well as quoting thousands of formal definitions. Get ~800 pages for two-thirds the price of these 11 !

Shameless plug!  Have you got yours yet? 


The 2026 edition includes a notable but easily-overlooked change regarding the identification of 'interested parties' (stakeholders) for an organisation's information security:  "Interested parties can include not only the organization’s customers, suppliers, business partners, employees, shareholders, but also government officials and, potentially, regulators. Competitors and criminals are also interested parties. Their requirements should be especially addressed by the information security controls of the ISMS. Indeed, a purpose of such information security controls is to protect the organization from the activities of such third parties."   So, an appreciation of the organisation's potential adversaries implies updating the risk identification, analysis, evaluation and treatment accordingly.  


ISO/IEC 27000 is quite liberal in its use of the word 'requirement' and similar terms such as 'need', 'necessary', 'objective', 'essential', 'expected'.  In ISO standards such as ISO/IEC 27001, 'requirement' generally means a statement formally defining or declaring something that is mandatory in order to claim conformity - a narrow interpretation.  ISO/IEC 27000 is not exclusively concerned with mandatory requirements for conformity assessment purposes, so has a more liberal interpretation.   


The information security controls in ISO/IEC 27001 (annex A), '27002, '27010, '27011, '27017 and '27019 are called “Candidate necessary information security controls” - a curiously ambiguous turn of phrase. ‘Necessary’ here is for management to determine according to its evaluation of the organisation's information risks relative to the risk appetite. ‘Candidate’ is clearly not ‘required’ and is less than ‘suggested’, but still some readers and inept auditors may feel the controls should or perhaps must be implemented.


[Spoiler alert] 


They don't.


The summary claims that ISO/IEC 27000 "clarifies how [18 ISO27k standards] relate to each other". While a table and diagram group the 18, the interrelationships or dependencies between them are not explained, unfortunately. For example, the 'sector-specific' standards ISO/IEC 27011, '27017 and '27019, identify information security controls (mostly drawn from ISO/IEC 27002) for telecoms, cloud and power companies, respectively: the processes of identifying and evaluating information risks to determine which controls are necessary, justifying the associated investments and implementation details, monitoring and managing them to achieve, maintain and gain assurance of their adequacy (efficiency and effectiveness) are covered by several other ISO27k standards. Again, those three standards do not mandate specific information security controls, nor are they comprehensive. They are generic suggestions.

This page last updated:

21 July 2026

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page