ISO/IEC 27000
ISO/IEC 27000:2026 — Information security, cybersecurity and privacy protection — Information Security Management Systems — Overview
(sixth edition)
Abstract
“ISO/IEC 27000 explains the core concepts and principles behind information security management systems, or ISMS. It provides an overview of the ISO/IEC 27000 family of standards, including ISO/IEC 27001, and clarifies how these documents relate to each other. The standard helps organizations understand the foundations of information security management before selecting, implementing or working with more specific ISMS standards.”
[Source: ISO.org)
Introduction
What is an Information Security Management System? What's the point? What is it for and what is it intended to achieve? How does it do that? What does it consist of? What is it not?
If questions of that nature puzzle you, this brief standard helps by explaining a 'management system', specifically a systematic way of managing information risks and information security controls.
Scope
ISO/IEC 27000 outlines the ISO27k 'family of standards':
ISO/IEC 27001 - ISMS requirements
ISO/IEC 27002 - information security controls
ISO/IEC 27003 - ISMS guidance
ISO/IEC 27004 - ISMS metrics
ISO/IEC 27005 - information security risk management
ISO/IEC 27006-1 - ISMS certification
ISO/IEC 27007 - ISMS auditing
ISO/IEC TS 27008 - information security controls assessment
ISO/IEC 27010 - inter-sector and inter-organizational communications
ISO/IEC 27011 - information security controls for telecommunications organizations
ISO/IEC 27013 - integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 (ITIL)
ISO/IEC 27014 - governance of information security
ISO/IEC TR 27016 - organizational economics
IISO/IEC 27017 - information security controls for cloud services
ISO/IEC 27019 - information security controls for energy utilities
ISO/IEC 27021 - ISMS professional competencies
ISO/IEC TR 27022 - ISMS processes
ISO/IEC 27028 - information security control attributes
It also mentions:
ISO 31000 - risk management guidelines
ISO/IEC 33004 - requirements for process reference, assessment and maturity
ISO/IEC 17021-1 - conformity assessment
ISO/IEC 17000 - conformity assessment vocabulary and general principles
ISO 19011 - management systems auditing
Structure
The 11-page standard has just three main clauses:
3: Terms and definitions - formally defines 12 key terms used in this standard, 7 of which are shortened definitions form other standards (without their notes) leaving 5 unique definitions. [1½ pages]
4: Concepts and principles - introduces information security, risk and security management, and management systems. [4 pages]
5: Documents* related to ISMS including ISO/IEC 27001 - succinct descriptions (just a sentence or so) of each of the standards numbered 1 to 18 above. [3 pages]
* Note: within ISO/IEC 27000, the term 'documents' means ISO and ISO/IEC standards, specifically, not documents in general. The mandatory and discretionary ISMS documents noted in ISO/IEC 27001 and other ISO27k standards are not described here, although a few are mentioned (e.g. ISMS scope and risk treatment plan).
Status
The first edition was published in 2009.
It was updated in 2012, 2014, 2016, 2018 and ... wait for it ... 2026.
The previous 5th edition was released by ISO for free as an introduction and promotion of ISO27k. A request has been lodged with ISO to make the current 6th edition free as well. Until that is approved and actioned, any copies of ISO/IEC 27000:2026 found loitering on the web are probably pirated.
Commentary
Due to an ISO policy decision, the current 2026 sixth edition dropped previous editions' extensive glossaries of dozens of ISO27k terms, leaving just a dozen actually used in this standard. However, the official definitions remain available online in ISO's Online Browsing Platform and IEC's Electropedia.
Alternatively, the Cybersecurity Hyperglossary defines well over 5,000 terms in plain English, as well as quoting thousands of formal definitions. Get ~800 pages for two-thirds the price of these 11 !
Shameless plug! Have you got yours yet?
The 2026 edition includes a notable but easily-overlooked change regarding the identification of 'interested parties' (stakeholders) for an organisation's information security: "Interested parties can include not only the organization’s customers, suppliers, business partners, employees, shareholders, but also government officials and, potentially, regulators. Competitors and criminals are also interested parties. Their requirements should be especially addressed by the information security controls of the ISMS. Indeed, a purpose of such information security controls is to protect the organization from the activities of such third parties." So, an appreciation of the organisation's potential adversaries implies updating the risk identification, analysis, evaluation and treatment accordingly.
ISO/IEC 27000 is quite liberal in its use of the word 'requirement' and similar terms such as 'need', 'necessary', 'objective', 'essential', 'expected'. In ISO standards such as ISO/IEC 27001, 'requirement' generally means a statement formally defining or declaring something that is mandatory in order to claim conformity - a narrow interpretation. ISO/IEC 27000 is not exclusively concerned with mandatory requirements for conformity assessment purposes, so has a more liberal interpretation.
The information security controls in ISO/IEC 27001 (annex A), '27002, '27010, '27011, '27017 and '27019 are called “Candidate necessary information security controls” - a curiously ambiguous turn of phrase. ‘Necessary’ here is for management to determine according to its evaluation of the organisation's information risks relative to the risk appetite. ‘Candidate’ is clearly not ‘required’ and is less than ‘suggested’, but still some readers and inept auditors may feel the controls should or perhaps must be implemented.
[Spoiler alert]
They don't.
The summary claims that ISO/IEC 27000 "clarifies how [18 ISO27k standards] relate to each other". While a table and diagram group the 18, the interrelationships or dependencies between them are not explained, unfortunately. For example, the 'sector-specific' standards ISO/IEC 27011, '27017 and '27019, identify information security controls (mostly drawn from ISO/IEC 27002) for telecoms, cloud and power companies, respectively: the processes of identifying and evaluating information risks to determine which controls are necessary, justifying the associated investments and implementation details, monitoring and managing them to achieve, maintain and gain assurance of their adequacy (efficiency and effectiveness) are covered by several other ISO27k standards. Again, those three standards do not mandate specific information security controls, nor are they comprehensive. They are generic suggestions.
