1.1 ISO/IEC 27000 Family Overview and Terminology
Key Takeaways
- ISO/IEC 27001:2022 is the sole normative, certifiable standard in the ISO 27000 family containing mandatory ISMS requirements across Clauses 4 through 10.
- ISO/IEC 27000 defines essential information security vocabulary, establishing authoritative terminology including the definition of an ISMS.
- ISO/IEC 27002:2022 provides guidance on control implementation, reorganizing 93 reference controls into 4 thematic categories: Organizational, People, Physical, and Technological.
- ISO/IEC 27003 provides implementation guidance, ISO/IEC 27004 specifies performance measurement metrics, and ISO/IEC 27005 governs information security risk management.
- Lead Auditors evaluate organizations strictly against ISO/IEC 27001 requirements; ISO/IEC 27002 controls serve as reference benchmarks rather than mandatory audit criteria.
1.1 ISO/IEC 27000 Family Overview and Terminology
Information security management within modern enterprises relies on a standardized, internationally recognized framework. The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) jointly publish the ISO/IEC 27000 family of standards (often referred to as the ISO 27000 series). For a PECB ISO/IEC 27001 Lead Auditor, mastering the structure, interrelationships, and precise terminology of this standard family is foundational. Auditing an Information Security Management System (ISMS) requires distinguishing between mandatory normative requirements and informative guidance.
Overview of the ISO/IEC 27000 Standard Family
The ISO/IEC 27000 series provides a comprehensive architecture covering all aspects of information security management, risk assessment, control implementation, and performance evaluation. Rather than existing as isolated documents, these standards form an integrated ecosystem designed to support organizations of any size or sector in protecting their information assets.
The Ecosystem Architecture
| Standard | Document Type | Core Focus & Function | Primary Target Audience |
|---|---|---|---|
| ISO/IEC 27000 | Overview & Vocabulary | Defines fundamental concepts, principles, and authoritative terms used across the standard family. | Auditors, Implementers, Consultants, Executives |
| ISO/IEC 27001 | Normative Requirements | Specifies mandatory requirements for establishing, implementing, maintaining, and continually improving an ISMS. | Lead Auditors, Certification Bodies, Compliance Officers |
| ISO/IEC 27002 | Code of Practice (Guidance) | Provides generic guidelines and implementation advice for information security controls listed in ISO 27001 Annex A. | Security Managers, System Administrators, Risk Officers |
| ISO/IEC 27003 | Guidance | Offers step-by-step guidance on designing and implementing an ISMS aligned with ISO/IEC 27001. | Project Managers, ISMS Implementation Teams |
| ISO/IEC 27004 | Guidance | Details metrics, monitoring, measurement, analysis, and evaluation methods for assessing ISMS effectiveness. | Security Analysts, Internal Auditors, Metrics Specialists |
| ISO/IEC 27005 | Guidance | Guidance on information security risk management, risk assessment methodology, and risk treatment strategies. | Risk Managers, Lead Risk Assessors, Chief Risk Officers |
Normative vs. Informative Standards
A critical distinction tested on the PECB Lead Auditor exam is the operational difference between normative and informative standards:
- Normative Standards (ISO/IEC 27001): Contains strict, mandatory requirements expressed using the auxiliary verb "shall". An organization seeking formal third-party certification must comply with every applicable clause in Clauses 4 through 10 of ISO/IEC 27001. If an organization fails to meet a normative requirement, the Lead Auditor must record a non-conformity.
- Informative Standards (ISO/IEC 27002, 27003, 27004, 27005): Contains recommendations, guidance, and best practices expressed using the auxiliary verb "should" or "may". Organizations cannot seek formal certification against ISO/IEC 27002 or 27005. Lead Auditors use informative standards to understand best-practice control implementations, but non-compliance with guidance in ISO 27002 does not automatically constitute a non-conformity against ISO 27001, provided the organization's control achieves the intended security objective.
Key Standards in the Family
ISO/IEC 27001: The Certifiable Requirement Standard
ISO/IEC 27001 defines the structural skeleton of an ISMS. It follows the High-Level Structure (HLS) / Harmonized Structure common to all ISO management system standards. Clauses 4 through 10 establish requirements for:
- Context of the organization (Clause 4): Understanding organizational context, interested parties, and ISMS scope.
- Leadership (Clause 5): Top management commitment, policy, roles, and responsibilities.
- Planning (Clause 6): Risk assessment, risk treatment planning, and information security objectives.
- Support (Clause 7): Resource allocation, competence, awareness, communication, and documented information.
- Operation (Clause 8): Operational planning, execution of risk assessments, and risk treatment execution.
- Performance evaluation (Clause 9): Monitoring, measurement, internal audit, and management review.
- Improvement (Clause 10): Non-conformity remediation, corrective actions, and continual improvement.
ISO/IEC 27002: Code of Practice for Information Security Controls
ISO/IEC 27002 serves as a reference catalog providing detailed guidance for implementing controls. In the ISO/IEC 27002:2022 update, the control structure underwent a major modernization. The older 2013 structure (114 controls across 14 domains) was consolidated into 93 controls across 4 thematic categories:
- Organizational controls (Clause 5): 37 controls governing policies, roles, threat intelligence, asset management, and cloud services.
- People controls (Clause 6): 8 controls addressing screening, employment terms, awareness training, and remote working.
- Physical controls (Clause 7): 14 controls covering physical security perimeters, equipment protection, and clear desk policy.
- Technological controls (Clause 8): 34 controls detailing access control, cryptography, secure coding, data masking, and logging.
Furthermore, ISO/IEC 27002:2022 introduced 5 attributes for each control: Control Type (Preventive, Detective, Corrective), Information Security Properties (CIA), Cybersecurity Concepts (Identify, Protect, Detect, Respond, Recover), Operational Capabilities, and Security Domains.
ISO/IEC 27003, 27004, and 27005
- ISO/IEC 27003 breaks down ISMS implementation into practical phases, helping organizations move from executive approval to full operational readiness.
- ISO/IEC 27004 guides the development of quantitative and qualitative metrics. It helps organizations fulfill ISO/IEC 27001 Clause 9.1 by defining what to measure, how to measure, and when to analyze results.
- ISO/IEC 27005 offers a structured approach to information security risk management, aligning closely with ISO 31000 principles. It provides methodologies for context establishment, risk identification, risk analysis, risk evaluation, and risk treatment.
Authoritative Vocabulary and Definitions (ISO/IEC 27000)
Precision in language is paramount during an audit. ISO/IEC 27000 defines key terms that Lead Auditors must use accurately:
- Information Security Management System (ISMS): Part of the overall management system, based on a business risk approach, to establish, implement, operate, monitor, review, maintain, and improve information security.
- Information Security: Preservation of confidentiality, integrity, and availability of information; in addition, other properties such as authenticity, accountability, non-repudiation, and reliability can also be involved.
- Statement of Applicability (SoA): Documented statement describing the applicable controls and justifications for inclusion, along with justifications for exclusion of any Annex A control.
- Top Management: Person or group of people who directs and controls an organization at the highest level.
Worked Audit Scenario: Evaluating Normative Boundaries
Scenario: During a Stage 2 certification audit of CloudTech Solutions, the Lead Auditor requests evidence for password complexity rules. CloudTech presents a custom pass-phrase policy requiring 15 characters without forced monthly password rotation. The auditor notes that ISO/IEC 27002:2022 Clause 8.5 suggests password management guidelines, but CloudTech's policy differs from traditional 90-day rotation rules.
Auditor Analysis: The auditor reviews ISO/IEC 27001 Annex A control A.8.5 (Privileged access rights) and A.5.15 (Access control). Since ISO/IEC 27002 is informative guidance, CloudTech is not obligated to follow traditional rotation if their 15-character pass-phrase policy effectively mitigates the risk of credential compromise. As long as CloudTech documented their rationale in their risk treatment plan and Statement of Applicability, no non-conformity exists.
Exam Tips for PECB Lead Auditor Candidates
- Remember Normative vs. Informative: ISO 27001 is the only certifiable normative standard. Never cite ISO 27002 or ISO 27005 as the clause violated in an Audit Non-Conformity Report.
- Know the 2022 Structural Shift: Be prepared to identify the 4 themes of ISO 27002:2022 (Organizational, People, Physical, Technological) and know there are 93 controls (reduced from 114).
- SoA Requirement: ISO/IEC 27001 Clause 6.1.3 requires the creation of a Statement of Applicability. Every single control in Annex A must be explicitly referenced as included or excluded with clear justification.
Which standard in the ISO/IEC 27000 series contains the normative requirements against which an organization can seek formal third-party certification?
In the ISO/IEC 27002:2022 update, how are the 93 reference information security controls organized?
During a Lead Auditor Stage 2 audit, an organization presents an information security performance measurement model based on ISO/IEC 27004. How should the auditor evaluate this framework?