Skip to main content
Category: Standards and Frameworks

ISO/IEC 27000

Also known as: ISO 27000, ISO/IEC 27000 series
Simply put

ISO/IEC 27000 is the introductory standard in the ISO/IEC 27000 family of information security standards, which includes the well-known ISO/IEC 27001. It provides a high-level overview of information security management systems along with the concepts and relationships that tie the family of standards together. It is not itself a certifiable standard; certification is achieved against ISO/IEC 27001.

Formal definition

ISO/IEC 27000 is the foundational document of the ISO/IEC 27000 family, published jointly by ISO and IEC, that presents an overview of information security management systems (ISMS) and describes the concepts and relationships among the standards in the series. Historically it also carried the subtitle 'Overview and vocabulary' and served as the family's consolidated terminology reference; practitioners should confirm the current edition and its stated scope, since the positioning and vocabulary content of this document has been revised and readers should verify which edition is in force before relying on it as an authoritative terminology source. Unlike ISO/IEC 27001, which contains the certifiable ISMS requirements in clauses 4 through 10 and reference controls in Annex A, ISO/IEC 27000 is explanatory in nature and organizations are not certified against it. Because ISO documents are periodically revised, any specific edition, publication date, or subtitle should be checked against the official ISO source rather than assumed.

Why it matters

ISO/IEC 27000 matters because it is the entry point into the broader ISO/IEC 27000 family of information security standards, providing the conceptual foundation that helps practitioners understand how the individual documents relate to one another. Organizations pursuing certification do so against ISO/IEC 27001, but ISO/IEC 27000 supplies the overview, concepts, and relationships that make the rest of the family coherent. Without a shared understanding of these foundational concepts, teams risk misinterpreting requirements or misaligning their information security management system (ISMS) efforts across the standards they rely on.

The standard is also important because its positioning has changed over time. Historically it carried the subtitle 'Overview and vocabulary' and served as the consolidated terminology reference for the family, but readers should confirm the current edition's scope before relying on it as an authoritative glossary, since the document has been revised to emphasize overview, concepts, and relationships rather than serving primarily as a terminology source. Because ISO documents are periodically revised, any specific edition, publication date, or subtitle should be verified against the official ISO source rather than assumed. Practitioners who cite an outdated edition or an obsolete subtitle risk basing decisions on superseded information.

Understanding ISO/IEC 27000 correctly also helps set expectations about certification boundaries. Because the document is explanatory rather than certifiable, organizations should not treat compliance with ISO/IEC 27000 as a certifiable outcome; certification is achieved against ISO/IEC 27001 and covers only the defined scope of the ISMS. Confusing the introductory standard with the certifiable one can lead to misstatements in audits, vendor questionnaires, and customer communications.

Who it's relevant to

Compliance and GRC managers
Those coordinating ISO/IEC 27001 certification efforts use ISO/IEC 27000 to orient their teams to the family's concepts and relationships before engaging with the certifiable requirements. They should confirm the current edition and its scope, and remember that certification is pursued against ISO/IEC 27001, not ISO/IEC 27000.
Security engineers and ISMS practitioners
Practitioners building or maintaining an information security management system benefit from the overview and conceptual framing that ISO/IEC 27000 provides, which helps them understand how individual standards in the series fit together. When they need authoritative terminology, they should verify which edition is in force rather than assuming the document still serves as the consolidated glossary.
Auditors and certification body personnel
Auditors reference ISO/IEC 27000 for foundational context, but assess conformity against the certifiable ISMS requirements in ISO/IEC 27001. They should ensure they are working from the current edition and are aware that the document's positioning and vocabulary content have been revised over time.
Vendor risk and procurement teams
Teams evaluating third parties should understand that an organization cannot be certified against ISO/IEC 27000 and that any ISO/IEC 27001 certificate covers only the defined scope of the ISMS. This distinction helps them interpret vendor claims accurately and avoid conflating the introductory standard with the certifiable one.

Inside ISO/IEC 27000

Position within the ISO/IEC 27000 family
ISO/IEC 27000 is the foundational document of the ISMS family of standards. It sits alongside the certifiable requirements standard (ISO/IEC 27001) and guidance standards (such as ISO/IEC 27002 for controls, and sector or topic extensions like ISO/IEC 27017 and ISO/IEC 27018), providing context for how the family fits together rather than stating certifiable requirements itself.
Overview, concepts and relationships
The current edition focuses on providing an overview of information security management systems and explaining the concepts and relationships among the standards in the family. Practitioners should treat it as an orientation document rather than as the definitive glossary.
Reduced vocabulary role
In earlier editions ISO/IEC 27000 served as the family's terminology reference under the subtitle 'Overview and vocabulary'. The more recent revision materially reduced the vocabulary content and repositioned the document toward overview, concepts and relationships, so it should no longer be relied upon as the authoritative terminology source for the family.
Relationship to certification and attestation frameworks
ISO/IEC 27000 relates only to the ISO/IEC 27000 family and its ISMS approach. It does not address SOC 2, which is an attestation examination performed by a licensed CPA firm under AICPA SSAE 18 resulting in a report. The two frameworks are distinct, and ISO/IEC 27000 provides no basis for SOC 2 scoping or reporting.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27000.

Is ISO/IEC 27000 the official glossary I should cite for definitions of ISMS terminology?
This is a common assumption that no longer holds cleanly. Earlier editions of ISO/IEC 27000 were positioned as the family's 'overview and vocabulary' document and were widely cited as the authoritative source for terms and definitions. However, the standard has been revised, and its terminology role has been substantially reduced in favor of an overview, concepts, and relationships focus. Because the availability and prominence of vocabulary content depends on which edition you are working from, you should confirm the specific edition in force and check its actual scope before relying on it as your terminology reference. Do not assume the current edition still functions as the family glossary.
Does the subtitle 'Overview and vocabulary' still accurately describe ISO/IEC 27000?
Not for the most recent revision. 'Overview and vocabulary' reflects the positioning of older editions and appears in a great deal of legacy documentation, training material, and secondary references. The standard has since been retitled and re-scoped to emphasize overview, concepts, and relationships rather than serving primarily as a terminology document. When you see the 'Overview and vocabulary' subtitle, treat it as an indicator that the source may reference a superseded edition, and verify the title and scope of the edition you actually intend to cite.
Do we need to purchase or certify against ISO/IEC 27000 to implement an ISMS?
No. ISO/IEC 27000 is a supporting document that provides context for the family of standards; it is not the certifiable standard. Certification is performed against ISO/IEC 27001, whose requirements sit in clauses 4 through 10, with reference controls listed in Annex A and selected via a Statement of Applicability informed by risk assessment. You cannot be certified against ISO/IEC 27000 itself. In most implementations, teams reference ISO/IEC 27000 for orientation and context while doing the substantive work against ISO/IEC 27001 and, for control guidance, ISO/IEC 27002.
How should we confirm which edition of ISO/IEC 27000 to reference in our documentation?
Check the official ISO catalog entry for the standard to identify the edition currently in force, its publication date, and its stated scope, and confirm whether any prior edition you were relying on has been withdrawn. This matters because the standard's role and content have shifted between editions, so a citation that was accurate under an older edition may be outdated. In most engagements it is good practice to record the specific edition and year in your document control metadata so auditors and reviewers can see exactly which version informed your work.
Where should we point auditors and staff for definitions of ISMS terms if ISO/IEC 27000's terminology role has changed?
Because the current positioning of ISO/IEC 27000 emphasizes overview and concepts rather than serving as a dedicated glossary, you should confirm within the edition in force which document or section now carries authoritative definitions before directing people to it. Depending on the edition and your scope, definitions may need to be sourced differently than in the past. Establish a single documented reference source for your organization's ISMS terminology, note the edition it draws from, and update it if a revision changes where official definitions reside.
How does ISO/IEC 27000 relate to the other standards we use for SOC 2 and ISO 27001 work?
ISO/IEC 27000 is part of the ISO/IEC 27000 family and provides context for standards such as ISO/IEC 27001 (the certifiable ISMS requirements) and ISO/IEC 27002 (control guidance), among others like ISO/IEC 27017 and ISO/IEC 27018 for cloud and privacy topics. It does not overlap with SOC 2, which is an AICPA attestation examination performed by a licensed CPA firm and evaluated against the Trust Services Criteria rather than ISO standards. Use ISO/IEC 27000 to orient stakeholders to how the ISO family fits together, but keep it separate from SOC 2 scoping, and remember that mapping between ISO 27001 and SOC 2 is partial rather than one-to-one.

Common misconceptions

ISO/IEC 27000 is the standard you get certified against.
ISO/IEC 27000 is not certifiable. Certification is conducted against ISO/IEC 27001, whose ISMS requirements sit in clauses 4 through 10, with Annex A reference controls selected via a Statement of Applicability. ISO/IEC 27000 provides overview and context only.
ISO/IEC 27000 is the permanent, authoritative glossary for all information security terms in the family.
The current edition of ISO/IEC 27000 was revised to focus on overview, concepts and relationships rather than serving primarily as a terminology document, and its dedicated vocabulary content was substantially reduced. Its long-standing legacy subtitle 'Overview and vocabulary' no longer describes the current edition, so users seeking official definitions should confirm the applicable edition and consult the currently designated authoritative source rather than assuming ISO/IEC 27000 remains the family glossary.
Understanding ISO/IEC 27000 satisfies SOC 2 or produces an equivalent outcome.
ISO/IEC 27000 pertains only to the ISO ISMS family and has no bearing on a SOC 2 examination. Mapping between ISO 27001 and SOC 2 is possible but partial, and satisfying one framework does not automatically satisfy the other.

Best practices

Confirm which edition of ISO/IEC 27000 you are referencing before relying on it, since the document was revised and the prior edition was withdrawn, and its role and content changed between versions.
Do not cite ISO/IEC 27000 as the definitive glossary for family terminology; verify the currently designated authoritative source for official definitions, because the dedicated vocabulary content was substantially reduced in the recent revision.
Use ISO/IEC 27000 for orientation on how the ISMS family fits together, then work from ISO/IEC 27001 clauses 4 through 10 for the certifiable ISMS requirements.
When citing control counts or Annex A structure, reference the specific ISO/IEC 27001 edition (for example, the 2022 revision restructured Annex A to 93 controls in four themes, versus 114 in the 2013 version), since numbers depend on the edition.
Avoid treating the legacy subtitle 'Overview and vocabulary' as current, and update internal documentation, alias lists, and references accordingly.
Keep ISO framework guidance separate from SOC 2 scoping decisions, and remember that any ISO 27001 certificate covers only the defined ISMS scope while a SOC 2 report attests only to the controls and period covered.