Skip to main content
Category: Governance and Roles

ISO/IEC 27014

Also known as: ISO/IEC 27014:2020, Governance of information security
Simply put

ISO/IEC 27014 is a guidance standard that helps organizations govern their information security at the leadership level, describing how those in charge can evaluate, direct, and monitor security activities. Unlike a certifiable standard, it offers concepts and processes for oversight rather than requirements that an organization is audited against. It is intended to work alongside ISO/IEC 27001 to connect security management with broader organizational governance.

Formal definition

ISO/IEC 27014 provides guidance on concepts, objectives, and processes for the governance of information security, enabling organizations to evaluate, direct, and monitor their information security activities. The current edition, ISO/IEC 27014:2020 (the second edition, superseding ISO/IEC 27014:2013), is positioned as a companion to ISO/IEC 27001 and addresses governance-level oversight rather than the ISMS requirements found in clauses 4 through 10 of ISO 27001. As a guidance document, it is not itself a certifiable standard; certification is issued against ISO/IEC 27001, not against ISO/IEC 27014. A subsequent revision was in development at the FDIS (Final Draft International Standard) stage; practitioners should confirm the applicable edition, since content and structure depend on the version referenced.

Why it matters

Information security governance is where accountability for security decisions ultimately rests with an organization's leadership and governing body, rather than with the operational teams that run controls day to day. ISO/IEC 27014 matters because it addresses this leadership layer directly, offering concepts and processes by which those in charge can evaluate, direct, and monitor security activities. Without this oversight function, an information security management system can operate in a vacuum, disconnected from the strategic objectives and risk appetite that the governing body is responsible for setting.

Because ISO/IEC 27014 is positioned as a companion to ISO/IEC 27001, it helps close a common gap: an ISMS may satisfy the certifiable requirements in clauses 4 through 10 while still lacking meaningful, sustained engagement from the top of the organization. The guidance frames security as a governance concern to be evaluated, directed, and monitored, which supports leadership in aligning security with broader organizational governance rather than treating it as a purely technical exercise.

It is important to understand what this standard is and is not. ISO/IEC 27014 is a guidance document, not a certifiable standard; certification is issued against ISO/IEC 27001, not against ISO/IEC 27014. Adopting its concepts does not, on its own, produce a certificate or guarantee any particular security outcome. Practitioners should also confirm which edition applies, since the current second edition, ISO/IEC 27014:2020, superseded the 2013 edition, and a subsequent revision was reported to be in development at the FDIS stage, meaning content and structure depend on the version referenced.

Who it's relevant to

Governing bodies and executive leadership
Boards, executives, and other members of the governing body are the primary audience, since the standard is oriented to those in charge of evaluating, directing, and monitoring information security. It helps leadership frame security as a governance responsibility aligned with organizational objectives, rather than delegating oversight entirely to technical teams.
ISMS owners and information security managers
Those responsible for an ISO/IEC 27001 ISMS can use ISO/IEC 27014 as a companion to strengthen the link between management-level security activities and governance-level oversight. It supports structuring reporting to leadership and demonstrating that security direction flows from, and is monitored by, the governing body. Note that certification remains against ISO/IEC 27001, not this guidance document.
GRC professionals and internal auditors
Governance, risk, and compliance practitioners and internal audit functions can reference the standard's evaluate-direct-monitor concepts when assessing how well security oversight is embedded at the leadership level. Because it is guidance rather than a certifiable requirement, it informs maturity and governance assessments rather than serving as a basis for formal certification.
Consultants advising on security governance
Advisors helping organizations mature their security programs can apply ISO/IEC 27014 to design governance processes that complement an ISO/IEC 27001 implementation. They should confirm the applicable edition with clients, since the 2020 second edition superseded the 2013 version and a further revision was reported to be in development.

Inside ISO/IEC 27014

Governance of information security
ISO/IEC 27014 addresses the governance of information security, focusing on how an organization's governing body directs and oversees information security activities. It is positioned above the operational management of security addressed by ISO/IEC 27001's ISMS requirements, dealing with direction, oversight, and accountability at the leadership level.
Relationship to the governing body and management
The standard distinguishes between the governing body (those with ultimate accountability, such as a board or equivalent) and executive management responsible for implementing security. It concerns how strategic direction is set and how the governing body evaluates and monitors security outcomes.
Guidance rather than certifiable requirements
ISO/IEC 27014 provides guidance and is not itself a certifiable standard in the way ISO/IEC 27001 is. Organizations do not receive a certificate against ISO/IEC 27014; instead, it informs how governance responsibilities can be structured to support an ISMS.
Position within the ISO/IEC 27000 family
It is one of several supporting standards in the ISO/IEC 27000 family. Where ISO/IEC 27001 sets the certifiable ISMS requirements and ISO/IEC 27002 provides implementation guidance for reference controls, ISO/IEC 27014 focuses specifically on the governance layer that sits above these.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27014.

Is ISO/IEC 27014 a certifiable standard like ISO/IEC 27001?
No. ISO/IEC 27014 provides guidance on the governance of information security and is not a certifiable requirements standard. Certification against a management system is achieved through ISO/IEC 27001, whose certifiable requirements sit in clauses 4 through 10. ISO/IEC 27014 supports governance activities but does not itself result in a certificate issued by an accredited certification body.
Does implementing ISO/IEC 27014 satisfy SOC 2 governance expectations?
Not automatically. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard against the Trust Services Criteria, and satisfying guidance in ISO/IEC 27014 does not by itself demonstrate that SOC 2 controls are suitably designed or operating effectively. Governance practices informed by ISO/IEC 27014 may support relevant Common Criteria, but any conclusion depends on the auditor, the scope, and the criteria selected for the engagement.
How does ISO/IEC 27014 relate to an ISO/IEC 27001 ISMS?
ISO/IEC 27014 offers guidance on how governing bodies can direct and oversee information security, which can complement the ISMS requirements defined in ISO/IEC 27001 clauses 4 through 10. In most implementations it is used to inform leadership and oversight activities rather than to replace or extend the certifiable requirements, so its use should be positioned as supporting governance depending on organizational scope.
Who within an organization typically uses ISO/IEC 27014?
Guidance on the governance of information security is generally intended for governing bodies and executive leadership, along with those who advise or report to them, such as GRC professionals and security leaders. The specific roles engaged depend on the organization's structure and how it has chosen to allocate governance and management responsibilities.
Can ISO/IEC 27014 be referenced in a Statement of Applicability?
The Statement of Applicability documents the selection of ISO/IEC 27001 Annex A reference controls informed by risk assessment, so ISO/IEC 27014 is not itself listed there as a control. Organizations may reference governance guidance to inform how oversight-related activities are directed, but the mechanics and content of the Statement of Applicability remain tied to the Annex A controls of the applicable ISO/IEC 27001 edition.
Should governance activities informed by ISO/IEC 27014 be documented for an audit or examination?
Documenting governance and oversight activities is generally advisable, since both ISO/IEC 27001 certification audits and SOC 2 examinations rely on evidence. However, what an assessor expects depends on the framework, the certification body or CPA firm, and the defined scope. Any evidence relating to governance should be prepared with the specific engagement's criteria and boundaries in mind rather than assuming a single universal requirement.

Common misconceptions

An organization can be certified against ISO/IEC 27014.
ISO/IEC 27014 provides governance guidance and is not the certifiable standard in the family. Certification is issued against ISO/IEC 27001 by an accredited certification body; ISO/IEC 27014 supports, but does not replace or extend, that certifiable scope.
ISO/IEC 27014 is interchangeable with ISO/IEC 27001 because both concern information security.
They address different layers. ISO/IEC 27001 sets the ISMS requirements (clauses 4 through 10) that are certifiable and references Annex A controls, whereas ISO/IEC 27014 focuses on governance direction and oversight by the governing body. Adopting one does not substitute for the other.
Following ISO/IEC 27014 guidance satisfies SOC 2 governance expectations automatically.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard against the Trust Services Criteria, and its outcome is a report, not a certification. Governance guidance from ISO/IEC 27014 may support relevant controls, but mapping to SOC 2 criteria is partial and depends on scope; satisfying one does not automatically satisfy the other.

Best practices

Position ISO/IEC 27014 as governance guidance layered above your certifiable ISO/IEC 27001 ISMS, rather than treating it as a source of certifiable requirements.
Clarify accountability between the governing body and executive management so that direction-setting and oversight of information security are distinct from day-to-day operational management.
Use the guidance to inform how the governing body evaluates and monitors security outcomes, feeding into, rather than duplicating, the ISMS requirements in clauses 4 through 10 of ISO/IEC 27001.
Where you pursue both ISO/IEC 27001 certification and a SOC 2 report, recognize that governance guidance may support controls in both but map coverage explicitly, since alignment between the frameworks is partial and scope-dependent.
Document the boundary of what governance guidance covers versus what is verified during ISO/IEC 27001 certification or a SOC 2 examination, to avoid overstating assurance.
Review governance arrangements against the current versions of the relevant standards, since guidance and referenced control structures can change across editions.