ISMS Family of Standards
The ISMS family of standards is a structured collection of related ISO/IEC standards, grouped under the 27000 numbering series, that together help organizations of any size manage information security. At its center is ISO/IEC 27001, the best-known standard for information security management systems (ISMS), which is supported by companion standards offering vocabulary, guidance, and specialized controls. The family is designed to help organizations manage security risk by implementing and operating an ISMS.
The ISMS family of standards (the ISO/IEC 27000 series) is a coordinated set of information security standards maintained by ISO/IEC, anchored by ISO/IEC 27001, which specifies the certifiable requirements for establishing, implementing, maintaining, and continually improving an information security management system. The family includes ISO/IEC 27000 (overview and vocabulary), ISO/IEC 27002 (guidance and implementation reference for controls), ISO/IEC 27005 (information security risk management guidance), and sector- or domain-specific standards such as ISO/IEC 27017 (cloud security controls) and ISO/IEC 27018 (protection of PII in public clouds). Within this family, standards serve distinct roles: some state requirements (normative), while others provide guidance, vocabulary, or extended control sets. Certification is issued by an accredited certification body against the requirements of ISO/IEC 27001; depending on the certification body and scope, accredited certificates addressing ISO/IEC 27017 and ISO/IEC 27018 are also available, typically as scope extensions to an ISO/IEC 27001 certification. Any resulting certificate covers only the defined scope of the ISMS. Practitioners should specify the standard edition and version when citing control counts or clause references, since these depend on the applicable revision; note in particular that Annex A of ISO/IEC 27001 was restructured in the 2022 revision (from 114 controls in the 2013 version to 93 controls organized into four themes). This family is distinct from AICPA SOC reporting frameworks; mapping between ISO/IEC 27001 and SOC 2 is possible but partial, and conformance with one does not automatically satisfy the other.
Why it matters
The ISMS family of standards matters because it gives organizations a coordinated, internationally recognized structure for managing information security risk rather than a single isolated document. At its center, ISO/IEC 27001 specifies the certifiable requirements for an information security management system, while companion standards supply the vocabulary, control guidance, and risk management methods that make those requirements practical to implement. For compliance managers and GRC professionals, this coherence means that decisions about controls, risk treatment, and terminology can all be traced back to a common, deliberately aligned body of standards.
The family also matters because it clarifies scope and role. Some standards in the series state requirements (normative), while others provide guidance, vocabulary, or extended control sets tailored to specific domains such as cloud services. Understanding which standard does what helps teams avoid misapplying a guidance document as if it were a requirements standard, and helps auditors and certification bodies frame the boundaries of an engagement correctly. Because any ISO/IEC 27001 certificate covers only the defined scope of the ISMS, knowing how the surrounding standards support and extend that scope is central to interpreting what a certificate actually attests to.
Finally, the family is relevant because it is distinct from other assurance frameworks. Mapping between ISO/IEC 27001 and SOC 2 is possible but partial, and conformance with one does not automatically satisfy the other. Organizations that pursue both need to understand where the ISMS family ends and other frameworks begin, so that they do not overstate the coverage of any single certificate or report.
Who it's relevant to
Inside ISMS Family of Standards
Common questions
Answers to the questions practitioners most commonly ask about ISMS Family of Standards.