3.1 The ISO/IEC 27000 Family
Key Takeaways
- ISO/IEC 27001 is the only certifiable standard in the family — it contains the mandatory ISMS requirements against which organizations are audited and certified
- ISO/IEC 27002 provides implementation guidance for controls; it is NOT certifiable and its controls are not automatically mandatory — selection happens through the Statement of Applicability (SoA) required by 27001 Annex A
- ISO/IEC 27000 is the vocabulary standard — it defines terms like ISMS, risk owner, and information security so all other family documents use consistent language
- ISO/IEC 27005 provides the information security risk management methodology that 27001 Clause 6.1.2 requires organizations to perform; 27005 itself is guidance, not a certifiable framework
- The 27000 family is published jointly by ISO and IEC through subcommittee SC 27; most standards are guidance documents, and only 27001 (and extensions like 27701) carry auditable requirements
The ISO/IEC 27000 family (also called the "27000 series" or "ISMS family of standards") is the set of International Standards developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) through subcommittee SC 27 (information security, cybersecurity and privacy protection). For the PECB ISO/IEC 27001 Foundation exam, you must know which standards exist, what each one does, and — most importantly — which are certifiable versus which are guidance. This distinction is the single most common source of exam traps in this chapter.
Why the Family Matters
No single standard in the family does everything. ISO/IEC 27001 gives you the mandatory requirements for an Information Security Management System (ISMS), but it deliberately does not tell you how to implement each control, how to measure effectiveness, how to run a risk assessment in detail, or how to audit a certification body. Each of those jobs is handled by a companion standard. Treating the family as one big document is wrong; treating it as a toolkit where 27001 is the spine and the others are specialized instruments is the correct mental model.
The Core Family Map
| Standard | Full Name (short) | Purpose | Certifiable? |
|---|---|---|---|
| ISO/IEC 27000 | Information security management systems — Overview and terminology | Defines vocabulary and overview; the "dictionary" of the family | No — guidance |
| ISO/IEC 27001 | Information security management systems — Requirements | Specifies the mandatory ISMS requirements (Clauses 4–10 + Annex A control objectives) | Yes — certifiable |
| ISO/IEC 27002 | Information security controls | Implementation guidance for controls; describes how each control can be implemented | No — guidance |
| ISO/IEC 27003 | Implementation guidance | Guidance for implementing an ISMS based on 27001 (focuses on Clauses 4–10) | No — guidance |
| ISO/IEC 27004 | Monitoring, measurement, analysis and evaluation | Guidance on how to measure and evaluate ISMS performance and effectiveness | No — guidance |
| ISO/IEC 27005 | Information security risk management | Methodology and guidance for information security risk assessment and treatment | No — guidance |
| ISO/IEC 27006 | Requirements for bodies providing audit and certification of ISMS | Requirements that certification bodies themselves must meet (the standard that accredits auditors) | No — requirements on certification bodies, not on the organization being certified |
| ISO/IEC 27007 | Guidelines for auditing ISMS | Auditing guidance complementing 19011 for ISMS audits | No — guidance |
| ISO/IEC 27701 | Privacy Information Management System (PIMS) | Extension to 27001 for privacy; adds PIMS requirements and controls | Yes — certifiable as an extension |
| ISO/IEC 27017 | Code of practice for cloud security | Cloud-specific controls extending 27002 | No — guidance |
| ISO/IEC 27018 | Code of practice for PII protection in public clouds | Cloud-specific controls for PII processors | No — guidance |
| ISO/IEC 27031 | ICT readiness for business continuity | Guidance on ensuring ICT supports business continuity | No — guidance |
| ISO/IEC 27033 | Network security | Network security guidance (multiple parts) | No — guidance |
| ISO/IEC 27035 | Information security incident management | Incident detection, reporting, response, and learning guidance | No — guidance |
| ISO/IEC 27037 | Digital evidence handling | Guidance for identification, collection, preservation of digital evidence | No — guidance |
How to Read the Table for the Exam
Only ISO/IEC 27001 (and its certified extensions such as 27701) is certifiable. That means an organization can engage an accredited certification body to audit against 27001's requirements and, if successful, receive a certificate. Every other standard in the family is guidance: organizations may use them, auditors may reference them, but no certificate is issued against them.
A common exam trick is to call a guidance standard "certifiable" or to imply that implementing 27002 means an organization is "27002-certified." Neither is true. A certification claim must always trace back to 27001 (or a named extension like 27701).
The Roles You Must Be Able to Match
- Vocabulary → 27000
- Requirements → 27001
- Control implementation guidance → 27002
- ISMS implementation guidance → 27003
- Measurement → 27004
- Risk management methodology → 27005
- Certification body requirements → 27006
- Auditing guidance → 27007
- Privacy extension → 27701
- Cloud security → 27017
- Cloud PII → 27018
- ICT readiness / business continuity → 27031
- Network security → 27033
- Incident management → 27035
- Digital evidence → 27037
Exam Scenarios and Traps
Trap 1: "We are 27002 certified."
Wrong. 27002 is guidance, not certifiable. An organization that has implemented 27002 controls and been audited is certified against 27001, not 27002. The audit uses 27001's requirements and Annex A control selection (via the Statement of Applicability) as the criteria; 27002 may be referenced for implementation detail.
Trap 2: "27006 certifies the organization."
Wrong direction. 27006 contains the requirements that certification bodies (and their auditors) must meet to be accredited to perform 27001 certification audits. It does not certify the organization being audited; it qualifies the auditor.
Trap 3: "27005 is the risk standard, so it replaces the risk clause in 27001."
No. 27001 Clause 6.1.2 (information security risk assessment) and Clause 6.1.3 (risk treatment) are the mandatory requirements. 27005 provides a methodology you can use to satisfy those clauses, but the obligation lives in 27001. You can use a different risk methodology (e.g., NIST RMF, OCTAVE) and still be 27001-certified, as long as the methodology meets 27001's requirements.
Trap 4: Confusing 27003 with 27001.
27003 is implementation guidance — it helps you build an ISMS that meets 27001's requirements. It is not itself a set of requirements. An organization cannot be "27003 certified."
Trap 5: Treating 27017 / 27018 as standalone certifications.
27017 and 27018 are codes of practice — guidance for cloud service providers and PII processors. They extend 27002's controls for cloud contexts. They are not separate certifications; a cloud provider certified against 27001 may demonstrate alignment with 27017/27018, but the certificate is still a 27001 certificate.
Trap 6: Assuming 27701 is "just guidance."
27701 is an extension to 27001 that adds Privacy Information Management System (PIMS) requirements and controls. Because it adds requirements to the 27001 framework, it IS certifiable — typically audited together with 27001, producing a combined 27001+27701 certificate. Do not classify 27701 as guidance on the exam.
How the Family Fits Together at Audit Time
When a certification body audits an organization against 27001:
- The auditor's qualifications come from 27006 and the auditing guidance in 27007 (with ISO 19011).
- The audit criteria are 27001's Clauses 4–10 and Annex A controls selected in the organization's Statement of Applicability.
- The control implementation guidance the auditor may reference to evaluate adequacy comes from 27002.
- The risk methodology the organization used (often 27005) is reviewed against 27001 Clause 6.1.2/6.1.3 requirements.
- The vocabulary used in findings is defined by 27000.
Understanding this flow answers a large share of "which standard applies when" questions on the Foundation exam.
Quick Mnemonic
- One certifiable core: 27001. Everything else is guidance, except extensions like 27701 that add requirements.
- Vocabulary first: 27000. You cannot read any other standard without it.
- Risk = 27005, Measure = 27004, Implement = 27003, Audit = 27007, Audit-the-auditor = 27006.
- Cloud = 27017/27018, Privacy = 27701, Incidents = 27035, Evidence = 27037, Continuity = 27031, Networks = 27033.
Master this mapping and you will answer the majority of family-identification questions correctly.
An organization claims it is "ISO/IEC 27002 certified" after implementing all controls in that standard. Which statement is correct?
Which standard contains the requirements that a certification body and its auditors must meet to be accredited to perform ISO/IEC 27001 certification audits?
A cloud service provider wants to demonstrate that it protects personally identifiable information (PII) in a public cloud. Which pair of standards most directly provides the relevant code of practice?
Which ISO/IEC 27000 family standard is certifiable as an extension that adds privacy requirements to an ISMS?