Skip to main content
Category: Standards and Frameworks

ISMS Family of Standards

Also known as: ISO/IEC 27000 family, ISO 27000 series, ISO/IEC 27000 series, ISO 27000 standards family
Simply put

The ISMS family of standards is a structured collection of related ISO/IEC standards, grouped under the 27000 numbering series, that together help organizations of any size manage information security. At its center is ISO/IEC 27001, the best-known standard for information security management systems (ISMS), which is supported by companion standards offering vocabulary, guidance, and specialized controls. The family is designed to help organizations manage security risk by implementing and operating an ISMS.

Formal definition

The ISMS family of standards (the ISO/IEC 27000 series) is a coordinated set of information security standards maintained by ISO/IEC, anchored by ISO/IEC 27001, which specifies the certifiable requirements for establishing, implementing, maintaining, and continually improving an information security management system. The family includes ISO/IEC 27000 (overview and vocabulary), ISO/IEC 27002 (guidance and implementation reference for controls), ISO/IEC 27005 (information security risk management guidance), and sector- or domain-specific standards such as ISO/IEC 27017 (cloud security controls) and ISO/IEC 27018 (protection of PII in public clouds). Within this family, standards serve distinct roles: some state requirements (normative), while others provide guidance, vocabulary, or extended control sets. Certification is issued by an accredited certification body against the requirements of ISO/IEC 27001; depending on the certification body and scope, accredited certificates addressing ISO/IEC 27017 and ISO/IEC 27018 are also available, typically as scope extensions to an ISO/IEC 27001 certification. Any resulting certificate covers only the defined scope of the ISMS. Practitioners should specify the standard edition and version when citing control counts or clause references, since these depend on the applicable revision; note in particular that Annex A of ISO/IEC 27001 was restructured in the 2022 revision (from 114 controls in the 2013 version to 93 controls organized into four themes). This family is distinct from AICPA SOC reporting frameworks; mapping between ISO/IEC 27001 and SOC 2 is possible but partial, and conformance with one does not automatically satisfy the other.

Why it matters

The ISMS family of standards matters because it gives organizations a coordinated, internationally recognized structure for managing information security risk rather than a single isolated document. At its center, ISO/IEC 27001 specifies the certifiable requirements for an information security management system, while companion standards supply the vocabulary, control guidance, and risk management methods that make those requirements practical to implement. For compliance managers and GRC professionals, this coherence means that decisions about controls, risk treatment, and terminology can all be traced back to a common, deliberately aligned body of standards.

The family also matters because it clarifies scope and role. Some standards in the series state requirements (normative), while others provide guidance, vocabulary, or extended control sets tailored to specific domains such as cloud services. Understanding which standard does what helps teams avoid misapplying a guidance document as if it were a requirements standard, and helps auditors and certification bodies frame the boundaries of an engagement correctly. Because any ISO/IEC 27001 certificate covers only the defined scope of the ISMS, knowing how the surrounding standards support and extend that scope is central to interpreting what a certificate actually attests to.

Finally, the family is relevant because it is distinct from other assurance frameworks. Mapping between ISO/IEC 27001 and SOC 2 is possible but partial, and conformance with one does not automatically satisfy the other. Organizations that pursue both need to understand where the ISMS family ends and other frameworks begin, so that they do not overstate the coverage of any single certificate or report.

Who it's relevant to

Compliance and GRC managers
These professionals rely on the family to understand which standard states requirements versus which provides guidance, so they can plan an ISMS implementation and define an appropriate certification scope. Because any certificate covers only the defined scope of the ISMS, they use the family structure to communicate accurately what a certification does and does not cover.
Auditors and certification bodies
Auditors assess conformance to the requirements of ISO/IEC 27001, and accredited certification bodies issue the resulting certificates. Depending on scope, they may also issue accredited certificates addressing ISO/IEC 27017 and ISO/IEC 27018, typically as scope extensions. They must specify the applicable edition when referencing clauses or control counts, given the 2022 restructuring of Annex A.
Security engineers and cloud teams
Engineers implementing controls draw on ISO/IEC 27002 for control guidance, ISO/IEC 27005 for risk management, and domain-specific standards such as ISO/IEC 27017 and ISO/IEC 27018 when operating in public cloud environments. They use the family to map technical controls to the ISMS and to support any cloud-focused scope extensions.
Organizations pursuing multiple frameworks
Teams working toward both ISO/IEC 27001 and AICPA SOC 2 use the family to keep the frameworks distinct. Because mapping between ISO/IEC 27001 and SOC 2 is possible but partial, and conformance with one does not automatically satisfy the other, they rely on the family's structure to avoid overstating equivalence.

Inside ISMS Family of Standards

ISO/IEC 27001
The core standard specifying requirements for an information security management system (ISMS). Its certifiable requirements sit in clauses 4 through 10, with Annex A providing reference controls selected via a Statement of Applicability informed by risk assessment. Accredited certification bodies issue certificates of conformity against this standard for a defined ISMS scope.
ISO/IEC 27002
A guidance standard providing implementation guidance and detailed control descriptions that correspond to the Annex A reference controls. It is advisory in nature and supports control selection and implementation rather than defining the certifiable management-system requirements found in ISO/IEC 27001.
ISO/IEC 27017
A code of practice offering cloud-specific information security controls and implementation guidance that extend the general controls, addressing shared responsibilities between cloud service providers and customers. In practice, accredited certification bodies issue certificates of conformity against it, often as a scope extension to an ISO/IEC 27001 certification.
ISO/IEC 27018
A code of practice addressing the protection of personally identifiable information (PII) in public cloud environments acting as PII processors. As with 27017, accredited certification bodies issue certificates of conformity against it, frequently alongside or as an extension to an ISO/IEC 27001 certification.
Statement of Applicability (SoA)
A required ISO/IEC 27001 document that records which reference controls are applicable, the justification for their inclusion or exclusion, and their implementation status. It links the risk assessment to selected controls and defines the boundary of what the certification covers.
Annex A reference controls
The catalogue of reference controls associated with ISO/IEC 27001. The 2022 revision restructured these into 93 controls organized under four themes, compared with 114 controls in the 2013 version; the applicable count depends on the edition cited.

Common questions

Answers to the questions practitioners most commonly ask about ISMS Family of Standards.

Does being certified to ISO/IEC 27001 mean my organization also conforms to the other standards in the ISMS family, like ISO/IEC 27017 or ISO/IEC 27018?
No. ISO/IEC 27001 contains the ISMS requirements in clauses 4 through 10, while the broader family provides supporting guidance and sector- or topic-specific controls. ISO/IEC 27002 offers implementation guidance for reference controls, and ISO/IEC 27017 and ISO/IEC 27018 address cloud security and cloud privacy respectively. A 27001 certificate covers the defined scope of your ISMS and does not automatically demonstrate conformity to these additional standards; where cloud-specific assurance is needed, organizations typically pursue those extensions separately, and accredited certification bodies do issue certificates addressing standards such as ISO/IEC 27017 and ISO/IEC 27018.
Is ISO/IEC 27002 something an organization gets certified against?
No. ISO/IEC 27002 is a guidance standard that provides implementation advice for information security controls; it is not the standard organizations are certified against. Certification is granted against ISO/IEC 27001, which specifies the ISMS requirements. Annex A of ISO/IEC 27001 lists reference controls, and organizations select applicable controls through a Statement of Applicability informed by risk assessment, using ISO/IEC 27002 for detailed guidance on how to implement them. Note that Annex A was restructured in the 2022 revision, so control counts and structure depend on the version you cite.
How do I decide which standards in the ISMS family are relevant to my organization?
Relevance depends on your scope, operating context, and risk assessment. ISO/IEC 27001 provides the core certifiable ISMS requirements, and ISO/IEC 27002 supports control implementation. If you provide or consume cloud services, ISO/IEC 27017 (cloud security) and ISO/IEC 27018 (protection of personally identifiable information in public clouds) are often relevant. In most engagements, organizations map their business drivers, contractual obligations, and identified risks to the standards that address those concerns rather than adopting the entire family.
Can I use ISO/IEC 27002 to guide control implementation even before pursuing certification?
Yes. Because ISO/IEC 27002 is guidance rather than a certifiable requirement, organizations often use it early to design and implement controls. When you later pursue ISO/IEC 27001 certification, you select applicable Annex A reference controls through the Statement of Applicability and justify inclusions and exclusions based on risk. Using 27002 up front can help build a control baseline, though the specific controls that end up in scope depend on your risk assessment and applicable requirements.
How do the cloud-focused standards fit alongside an ISO/IEC 27001 ISMS?
ISO/IEC 27017 and ISO/IEC 27018 are typically implemented as extensions to an existing ISMS rather than as replacements for ISO/IEC 27001. They add cloud-specific control guidance and, respectively, cloud privacy considerations. In practice, organizations often build the ISMS to 27001 first and then extend the scope to address cloud controls, with accredited certification bodies able to issue certificates covering these additional standards. The exact approach depends on your certification body, scope, and the assurance your customers require.
How does an ISMS family approach relate to a SOC 2 examination?
They are distinct assurance mechanisms. A SOC 2 examination is an attestation performed by a licensed CPA firm under the AICPA SSAE 18 standard against the Trust Services Criteria, resulting in a report. An ISO/IEC 27001 outcome is a certification issued by an accredited certification body against a management system standard. Mapping between the Trust Services Criteria and ISO/IEC 27001 clauses and Annex A controls is possible but partial, so satisfying one does not automatically satisfy the other. Organizations subject to both often maintain a combined control set while keeping the two assessment processes and their deliverables separate.

Common misconceptions

An ISO 27001 certificate demonstrates that an organization is fully secure and free from breaches.
An ISO/IEC 27001 certificate attests that an ISMS conforming to the standard's requirements exists within a defined scope at the time of assessment. It does not guarantee freedom from breaches, and it covers only the boundaries of the certified ISMS.
Only ISO/IEC 27001 within the family can be certified, and standards such as 27017 and 27018 are merely guidance that cannot support certification.
ISO/IEC 27017 and ISO/IEC 27018 are codes of practice, but accredited certification bodies do issue certificates of conformity against them, typically as scope extensions to an ISO/IEC 27001 certification. Several major cloud providers publish such accredited certificates. ISO/IEC 27002, by contrast, functions as implementation guidance rather than a certification basis.
Achieving ISO/IEC 27001 certification is equivalent to holding a SOC 2 report, so one satisfies the other.
The two frameworks are distinct: ISO/IEC 27001 is a certification against a management system standard issued by an accredited certification body, while SOC 2 is an attestation examination performed by a licensed CPA firm resulting in a report. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other.

Best practices

Always specify the ISO/IEC 27001 edition (for example, 2013 versus 2022) when citing Annex A control counts, since the numbers and structure differ between versions.
Maintain a current Statement of Applicability that justifies inclusion and exclusion of controls and traces each back to the risk assessment, as this defines the boundary of what certification covers.
Use ISO/IEC 27002 as implementation guidance to support control selection while relying on ISO/IEC 27001 clauses 4 through 10 for the certifiable management-system requirements.
Where cloud services are in scope, consider ISO/IEC 27017 and ISO/IEC 27018 as scope extensions to an ISO/IEC 27001 certification, and confirm with the accredited certification body which certificates of conformity they can issue.
Clearly document the ISMS scope so stakeholders understand that certification applies only to the defined boundary and does not guarantee freedom from breaches.
When aligning with SOC 2, treat any mapping between the frameworks as partial, and confirm requirements independently rather than assuming one certification or report satisfies the other.