ISO/IEC 27014
ISO/IEC 27014 is a guidance standard that helps organizations govern their information security at the leadership level, describing how those in charge can evaluate, direct, and monitor security activities. Unlike a certifiable standard, it offers concepts and processes for oversight rather than requirements that an organization is audited against. It is intended to work alongside ISO/IEC 27001 to connect security management with broader organizational governance.
ISO/IEC 27014 provides guidance on concepts, objectives, and processes for the governance of information security, enabling organizations to evaluate, direct, and monitor their information security activities. The current edition, ISO/IEC 27014:2020 (the second edition, superseding ISO/IEC 27014:2013), is positioned as a companion to ISO/IEC 27001 and addresses governance-level oversight rather than the ISMS requirements found in clauses 4 through 10 of ISO 27001. As a guidance document, it is not itself a certifiable standard; certification is issued against ISO/IEC 27001, not against ISO/IEC 27014. A subsequent revision was in development at the FDIS (Final Draft International Standard) stage; practitioners should confirm the applicable edition, since content and structure depend on the version referenced.
Why it matters
Information security governance is where accountability for security decisions ultimately rests with an organization's leadership and governing body, rather than with the operational teams that run controls day to day. ISO/IEC 27014 matters because it addresses this leadership layer directly, offering concepts and processes by which those in charge can evaluate, direct, and monitor security activities. Without this oversight function, an information security management system can operate in a vacuum, disconnected from the strategic objectives and risk appetite that the governing body is responsible for setting.
Because ISO/IEC 27014 is positioned as a companion to ISO/IEC 27001, it helps close a common gap: an ISMS may satisfy the certifiable requirements in clauses 4 through 10 while still lacking meaningful, sustained engagement from the top of the organization. The guidance frames security as a governance concern to be evaluated, directed, and monitored, which supports leadership in aligning security with broader organizational governance rather than treating it as a purely technical exercise.
It is important to understand what this standard is and is not. ISO/IEC 27014 is a guidance document, not a certifiable standard; certification is issued against ISO/IEC 27001, not against ISO/IEC 27014. Adopting its concepts does not, on its own, produce a certificate or guarantee any particular security outcome. Practitioners should also confirm which edition applies, since the current second edition, ISO/IEC 27014:2020, superseded the 2013 edition, and a subsequent revision was reported to be in development at the FDIS stage, meaning content and structure depend on the version referenced.
Who it's relevant to
Inside ISO/IEC 27014
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27014.