3.1 The ISO/IEC 27000 Family

Key Takeaways

  • ISO/IEC 27001 is the only certifiable standard in the family — it contains the mandatory ISMS requirements against which organizations are audited and certified
  • ISO/IEC 27002 provides implementation guidance for controls; it is NOT certifiable and its controls are not automatically mandatory — selection happens through the Statement of Applicability (SoA) required by 27001 Annex A
  • ISO/IEC 27000 is the vocabulary standard — it defines terms like ISMS, risk owner, and information security so all other family documents use consistent language
  • ISO/IEC 27005 provides the information security risk management methodology that 27001 Clause 6.1.2 requires organizations to perform; 27005 itself is guidance, not a certifiable framework
  • The 27000 family is published jointly by ISO and IEC through subcommittee SC 27; most standards are guidance documents, and only 27001 (and extensions like 27701) carry auditable requirements
Last updated: July 2026

The ISO/IEC 27000 family (also called the "27000 series" or "ISMS family of standards") is the set of International Standards developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) through subcommittee SC 27 (information security, cybersecurity and privacy protection). For the PECB ISO/IEC 27001 Foundation exam, you must know which standards exist, what each one does, and — most importantly — which are certifiable versus which are guidance. This distinction is the single most common source of exam traps in this chapter.

Why the Family Matters

No single standard in the family does everything. ISO/IEC 27001 gives you the mandatory requirements for an Information Security Management System (ISMS), but it deliberately does not tell you how to implement each control, how to measure effectiveness, how to run a risk assessment in detail, or how to audit a certification body. Each of those jobs is handled by a companion standard. Treating the family as one big document is wrong; treating it as a toolkit where 27001 is the spine and the others are specialized instruments is the correct mental model.

The Core Family Map

StandardFull Name (short)PurposeCertifiable?
ISO/IEC 27000Information security management systems — Overview and terminologyDefines vocabulary and overview; the "dictionary" of the familyNo — guidance
ISO/IEC 27001Information security management systems — RequirementsSpecifies the mandatory ISMS requirements (Clauses 4–10 + Annex A control objectives)Yes — certifiable
ISO/IEC 27002Information security controlsImplementation guidance for controls; describes how each control can be implementedNo — guidance
ISO/IEC 27003Implementation guidanceGuidance for implementing an ISMS based on 27001 (focuses on Clauses 4–10)No — guidance
ISO/IEC 27004Monitoring, measurement, analysis and evaluationGuidance on how to measure and evaluate ISMS performance and effectivenessNo — guidance
ISO/IEC 27005Information security risk managementMethodology and guidance for information security risk assessment and treatmentNo — guidance
ISO/IEC 27006Requirements for bodies providing audit and certification of ISMSRequirements that certification bodies themselves must meet (the standard that accredits auditors)No — requirements on certification bodies, not on the organization being certified
ISO/IEC 27007Guidelines for auditing ISMSAuditing guidance complementing 19011 for ISMS auditsNo — guidance
ISO/IEC 27701Privacy Information Management System (PIMS)Extension to 27001 for privacy; adds PIMS requirements and controlsYes — certifiable as an extension
ISO/IEC 27017Code of practice for cloud securityCloud-specific controls extending 27002No — guidance
ISO/IEC 27018Code of practice for PII protection in public cloudsCloud-specific controls for PII processorsNo — guidance
ISO/IEC 27031ICT readiness for business continuityGuidance on ensuring ICT supports business continuityNo — guidance
ISO/IEC 27033Network securityNetwork security guidance (multiple parts)No — guidance
ISO/IEC 27035Information security incident managementIncident detection, reporting, response, and learning guidanceNo — guidance
ISO/IEC 27037Digital evidence handlingGuidance for identification, collection, preservation of digital evidenceNo — guidance

How to Read the Table for the Exam

Only ISO/IEC 27001 (and its certified extensions such as 27701) is certifiable. That means an organization can engage an accredited certification body to audit against 27001's requirements and, if successful, receive a certificate. Every other standard in the family is guidance: organizations may use them, auditors may reference them, but no certificate is issued against them.

A common exam trick is to call a guidance standard "certifiable" or to imply that implementing 27002 means an organization is "27002-certified." Neither is true. A certification claim must always trace back to 27001 (or a named extension like 27701).

The Roles You Must Be Able to Match

  • Vocabulary → 27000
  • Requirements → 27001
  • Control implementation guidance → 27002
  • ISMS implementation guidance → 27003
  • Measurement → 27004
  • Risk management methodology → 27005
  • Certification body requirements → 27006
  • Auditing guidance → 27007
  • Privacy extension → 27701
  • Cloud security → 27017
  • Cloud PII → 27018
  • ICT readiness / business continuity → 27031
  • Network security → 27033
  • Incident management → 27035
  • Digital evidence → 27037

Exam Scenarios and Traps

Trap 1: "We are 27002 certified."

Wrong. 27002 is guidance, not certifiable. An organization that has implemented 27002 controls and been audited is certified against 27001, not 27002. The audit uses 27001's requirements and Annex A control selection (via the Statement of Applicability) as the criteria; 27002 may be referenced for implementation detail.

Trap 2: "27006 certifies the organization."

Wrong direction. 27006 contains the requirements that certification bodies (and their auditors) must meet to be accredited to perform 27001 certification audits. It does not certify the organization being audited; it qualifies the auditor.

Trap 3: "27005 is the risk standard, so it replaces the risk clause in 27001."

No. 27001 Clause 6.1.2 (information security risk assessment) and Clause 6.1.3 (risk treatment) are the mandatory requirements. 27005 provides a methodology you can use to satisfy those clauses, but the obligation lives in 27001. You can use a different risk methodology (e.g., NIST RMF, OCTAVE) and still be 27001-certified, as long as the methodology meets 27001's requirements.

Trap 4: Confusing 27003 with 27001.

27003 is implementation guidance — it helps you build an ISMS that meets 27001's requirements. It is not itself a set of requirements. An organization cannot be "27003 certified."

Trap 5: Treating 27017 / 27018 as standalone certifications.

27017 and 27018 are codes of practice — guidance for cloud service providers and PII processors. They extend 27002's controls for cloud contexts. They are not separate certifications; a cloud provider certified against 27001 may demonstrate alignment with 27017/27018, but the certificate is still a 27001 certificate.

Trap 6: Assuming 27701 is "just guidance."

27701 is an extension to 27001 that adds Privacy Information Management System (PIMS) requirements and controls. Because it adds requirements to the 27001 framework, it IS certifiable — typically audited together with 27001, producing a combined 27001+27701 certificate. Do not classify 27701 as guidance on the exam.

How the Family Fits Together at Audit Time

When a certification body audits an organization against 27001:

  1. The auditor's qualifications come from 27006 and the auditing guidance in 27007 (with ISO 19011).
  2. The audit criteria are 27001's Clauses 4–10 and Annex A controls selected in the organization's Statement of Applicability.
  3. The control implementation guidance the auditor may reference to evaluate adequacy comes from 27002.
  4. The risk methodology the organization used (often 27005) is reviewed against 27001 Clause 6.1.2/6.1.3 requirements.
  5. The vocabulary used in findings is defined by 27000.

Understanding this flow answers a large share of "which standard applies when" questions on the Foundation exam.

Quick Mnemonic

  • One certifiable core: 27001. Everything else is guidance, except extensions like 27701 that add requirements.
  • Vocabulary first: 27000. You cannot read any other standard without it.
  • Risk = 27005, Measure = 27004, Implement = 27003, Audit = 27007, Audit-the-auditor = 27006.
  • Cloud = 27017/27018, Privacy = 27701, Incidents = 27035, Evidence = 27037, Continuity = 27031, Networks = 27033.

Master this mapping and you will answer the majority of family-identification questions correctly.

Test Your Knowledge

An organization claims it is "ISO/IEC 27002 certified" after implementing all controls in that standard. Which statement is correct?

A
B
C
D
Test Your Knowledge

Which standard contains the requirements that a certification body and its auditors must meet to be accredited to perform ISO/IEC 27001 certification audits?

A
B
C
D
Test Your Knowledge

A cloud service provider wants to demonstrate that it protects personally identifiable information (PII) in a public cloud. Which pair of standards most directly provides the relevant code of practice?

A
B
C
D
Test Your Knowledge

Which ISO/IEC 27000 family standard is certifiable as an extension that adds privacy requirements to an ISMS?

A
B
C
D