ISO/IEC 27000
ISO/IEC 27000 is the introductory standard in the ISO/IEC 27000 family of information security standards, which includes the well-known ISO/IEC 27001. It provides a high-level overview of information security management systems along with the concepts and relationships that tie the family of standards together. It is not itself a certifiable standard; certification is achieved against ISO/IEC 27001.
ISO/IEC 27000 is the foundational document of the ISO/IEC 27000 family, published jointly by ISO and IEC, that presents an overview of information security management systems (ISMS) and describes the concepts and relationships among the standards in the series. Historically it also carried the subtitle 'Overview and vocabulary' and served as the family's consolidated terminology reference; practitioners should confirm the current edition and its stated scope, since the positioning and vocabulary content of this document has been revised and readers should verify which edition is in force before relying on it as an authoritative terminology source. Unlike ISO/IEC 27001, which contains the certifiable ISMS requirements in clauses 4 through 10 and reference controls in Annex A, ISO/IEC 27000 is explanatory in nature and organizations are not certified against it. Because ISO documents are periodically revised, any specific edition, publication date, or subtitle should be checked against the official ISO source rather than assumed.
Why it matters
ISO/IEC 27000 matters because it is the entry point into the broader ISO/IEC 27000 family of information security standards, providing the conceptual foundation that helps practitioners understand how the individual documents relate to one another. Organizations pursuing certification do so against ISO/IEC 27001, but ISO/IEC 27000 supplies the overview, concepts, and relationships that make the rest of the family coherent. Without a shared understanding of these foundational concepts, teams risk misinterpreting requirements or misaligning their information security management system (ISMS) efforts across the standards they rely on.
The standard is also important because its positioning has changed over time. Historically it carried the subtitle 'Overview and vocabulary' and served as the consolidated terminology reference for the family, but readers should confirm the current edition's scope before relying on it as an authoritative glossary, since the document has been revised to emphasize overview, concepts, and relationships rather than serving primarily as a terminology source. Because ISO documents are periodically revised, any specific edition, publication date, or subtitle should be verified against the official ISO source rather than assumed. Practitioners who cite an outdated edition or an obsolete subtitle risk basing decisions on superseded information.
Understanding ISO/IEC 27000 correctly also helps set expectations about certification boundaries. Because the document is explanatory rather than certifiable, organizations should not treat compliance with ISO/IEC 27000 as a certifiable outcome; certification is achieved against ISO/IEC 27001 and covers only the defined scope of the ISMS. Confusing the introductory standard with the certifiable one can lead to misstatements in audits, vendor questionnaires, and customer communications.
Who it's relevant to
Inside ISO/IEC 27000
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27000.