1.1 ISO/IEC 27000 Standards Family & Information Security Principles

Key Takeaways

  • The ISO/IEC 27000 family provides a structured, internationally recognized framework for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an Information Security Management System (ISMS).
  • ISO/IEC 27001:2022 is the sole certifiable requirements standard within the family, featuring 7 normative clauses (Clauses 4–10) and 93 Annex A controls structured across four organizational themes.
  • ISO/IEC 27002:2022 serves as a non-certifiable code of practice providing guidance for control implementation, introducing 5 control attributes (Control types, Information security properties, Cybersecurity concepts, Operational capabilities, Security domains).
  • Information security revolves around protecting the CIA triad—Confidentiality, Integrity, and Availability—supplemented by extended principles including Authenticity, Accountability, Non-repudiation, and Reliability.
  • An effective ISMS incorporates risk-based management, top management leadership, process-oriented thinking, and continuous alignment with strategic organizational objectives.
Last updated: July 2026

1.1 ISO/IEC 27000 Standards Family & Information Security Principles

Information security management relies on standardized frameworks to ensure that organizational assets remain protected against evolving threat landscapes. The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) jointly publish the ISO/IEC 27000 family of standards. For a Lead Implementer, mastering the structure, vocabulary, and operational relationships between these standards is essential for driving successful certification projects and aligning security governance with executive strategy.


Overview of the ISO/IEC 27000 Standards Family

The ISO/IEC 27000 series comprises dozens of standards, guidance documents, and technical reports. However, six core standards form the foundation of any Information Security Management System (ISMS) implementation project:

1. ISO/IEC 27000 — Overview and Vocabulary

ISO/IEC 27000 provides the foundational language, definitions, and overarching concepts used throughout the entire standard series. Key normative definitions essential for Lead Implementers include:

  • Information Security Management System (ISMS): That part of the overall management system, based on a business risk approach, to establish, implement, operate, monitor, review, maintain, and improve information security.
  • Risk: The effect of uncertainty on objectives. Risk is measured in terms of a combination of the likelihood of an event and its consequence.
  • Vulnerability: A weakness of an asset or control that can be exploited by one or more threats.
  • Threat: A potential cause of an unwanted incident, which may result in harm to a system or organization.
  • Control: A measure that modifies risk. Controls include policies, procedures, roles, technical mechanisms, and physical safeguards.

2. ISO/IEC 27001:2022 — Requirements Standard

ISO/IEC 27001 is the only certifiable standard in the family. Organizations undergo formal third-party audit against ISO/IEC 27001 to achieve accredited certification. It specifies mandatory requirements across two distinct parts:

  • Normative Clauses 4 through 10: Requirements based on the ISO Harmonized Structure (formerly High-Level Structure / HLS), covering Context (Clause 4), Leadership (Clause 5), Planning (Clause 6), Support (Clause 7), Operation (Clause 8), Performance Evaluation (Clause 9), and Improvement (Clause 10).
  • Annex A: A mandatory reference list of control objectives and controls. The ISO/IEC 27001:2022 revision reorganized Annex A from 114 controls across 14 domains (in the 2013 version) into 93 controls across 4 themes:
    1. Organizational controls (37 controls)
    2. People controls (8 controls)
    3. Physical controls (14 controls)
    4. Technological controls (34 controls)

3. ISO/IEC 27002:2022 — Code of Practice for Information Security Controls

ISO/IEC 27002 provides generic, non-mandatory guidance for implementing the controls listed in ISO/IEC 27001 Annex A. It cannot be used as a stand-alone certification specification. The 27002:2022 edition introduces a standardized attribute taxonomy to help organizations categorize, filter, and view controls:

  • Control Type: Preventive, Detective, Corrective.
  • Information Security Properties: Confidentiality, Integrity, Availability.
  • Cybersecurity Concepts: Identify, Protect, Detect, Respond, Recover (aligned with NIST CSF).
  • Operational Capabilities: Governance, Asset Management, Information Protection, Human Resource Security, Physical Security, System and Network Security, Application Security, Configuration Management, Identity and Access Management, Threat and Vulnerability Management, Continuity, Supplier Relationships Security, Legal and Compliance, Information Security Event Management, Information Security Assurance.
  • Security Domains: Governance and Ecosystem, Protection, Defense, Resilience.

4. Supporting Standards (27003, 27004, 27005)

  • ISO/IEC 27003: Offers step-by-step guidance on designing and implementing an ISMS in alignment with ISO/IEC 27001 requirements.
  • ISO/IEC 27004: Provides guidance on developing metrics, monitoring mechanisms, measurement methods, and reporting frameworks to evaluate ISMS effectiveness (fulfilling Clause 9.1 requirements).
  • ISO/IEC 27005: Offers comprehensive frameworks, methodologies, and guidance for information security risk assessment and risk treatment (supporting Clause 6.1 requirements).

ISO/IEC Standards Family Comparison Matrix

StandardTitle / Primary FocusCertifiable?Target Audience & Primary Use Case
ISO/IEC 27000Vocabulary & ConceptsNoTerms, definitions, and overarching ISMS principles for all practitioners.
ISO/IEC 27001:2022ISMS RequirementsYesOrganizations seeking formal ISMS certification; auditors and Lead Implementers.
ISO/IEC 27002:2022Code of Practice for ControlsNoSecurity engineers and implementers designing specific control safeguards.
ISO/IEC 27003Implementation GuidanceNoProject managers and Lead Implementers building ISMS project roadmaps.
ISO/IEC 27004Monitoring & MeasurementNoSecurity metrics specialists evaluating ISMS operational performance.
ISO/IEC 27005Risk Management GuidanceNoRisk officers conducting threat identification, vulnerability analysis, and risk treatment.

Fundamental Information Security Principles

At its core, information security is about managing risk to preserve three essential attributes of information assets, collectively known as the CIA Triad:

                 [ Confidentiality ]
                        /   \
                       /     \
                      /   ▲   \
                     /  ISMS   \
                    /           \
         [ Integrity ] --------- [ Availability ]

1. The CIA Triad

  • Confidentiality: Ensuring that information is accessible only to authorized individuals, entities, or processes. Breaches occur through unauthorized disclosure, wiretapping, or improper access controls.
  • Integrity: Safeguarding the accuracy, completeness, and authenticity of information and processing methods. Breaches occur when unauthorized modifications, data corruption, or tampering take place.
  • Availability: Ensuring that authorized users have timely and reliable access to information and associated assets when required. Breaches stem from system outages, Denial of Service (DoS) attacks, hardware failures, or ransomware encryption.

2. Extended Security Principles

Modern ISMS implementations expand beyond the traditional CIA triad to enforce additional supporting properties:

  • Authenticity: Verifying that an input, message, or party is genuine and originates from the claimed source.
  • Accountability: Ensuring that actions of an entity can be traced uniquely to that entity, enabling non-repudiation and forensic auditing.
  • Non-repudiation: Preventing an entity from denying the origination or execution of a specific transaction or action.
  • Reliability: Consistently executing processes and systems according to expected behavior and specifications.

Core Principles of an ISO/IEC 27001 ISMS

A successful ISMS implementation is guided by key management principles:

  1. Risk-Based Approach: Security measures must not be implemented arbitrarily. Controls must be selected based on explicit information security risk assessments that evaluate threats, vulnerabilities, likelihood, and business impact.
  2. Top Management Leadership & Alignment: Security is an executive leadership responsibility, not merely an IT function. The ISMS must align directly with the organization’s strategic objectives and business context.
  3. Process Approach & Harmonized Structure: The ISMS follows a structured process model that integrates seamlessly with other ISO management systems (such as ISO 9001 for quality or ISO 22301 for business continuity) via the Harmonized Structure.
  4. Continual Improvement: Based on the Plan-Do-Check-Act (PDCA) legacy model, an ISMS is dynamic. Organizations must continually monitor performance, conduct audits, execute management reviews, and implement corrective actions.

Practical Implementation Scenario

Scenario: FinancialTech Ltd., a cloud-based payment processor, is preparing for ISO/IEC 27001 certification. The Lead Implementer conducts an initial orientation for the executive committee. The Chief Technology Officer (CTO) suggests adopting ISO/IEC 27002 as the primary standard for compliance certification.

Lead Implementer Guidance: The Lead Implementer clarifies that third-party certification audits evaluate compliance strictly against ISO/IEC 27001:2022 (specifically Clauses 4–10 and the Statement of Applicability derived from Annex A). ISO/IEC 27002:2022 serves as an advisory implementation guide detailing how controls can be implemented and categorized using attribute taxonomy. The organization must define its ISMS requirements using 27001, while leveraging 27002 control guidance to select appropriate safeguards for mitigated risks.

Loading diagram...
ISO/IEC 27000 Standards Family Operational Relationships
Test Your Knowledge

An organization is preparing for an accredited third-party certification audit of its Information Security Management System. Which ISO/IEC standard contains the mandatory requirements against which the organization will be formally audited?

A
B
C
D
Test Your Knowledge

In the ISO/IEC 27001:2022 revision, how are the Annex A information security controls structured compared to the 2013 version?

A
B
C
D
Test Your Knowledge

A Lead Implementer is establishing control tags using ISO/IEC 27002:2022 guidance. Which set of properties represents the five attribute types introduced in ISO/IEC 27002:2022 to assist in control taxonomy and filtering?

A
B
C
D