ISO/IEC 27021
ISO/IEC 27021 is an international standard that describes the skills and knowledge a professional should have to lead or work on an organization's information security management system (ISMS). Rather than setting requirements for the security program itself, it defines what makes someone competent to run one. It is used to guide training, hiring, and professional development for ISMS practitioners.
ISO/IEC 27021:2017 specifies the competence requirements for information security management systems professionals who lead or are involved in establishing, implementing, maintaining, and continually improving one or more ISMS processes as defined in the ISO/IEC 27001 family of standards. It articulates the business and information security management knowledge and skills expected of such professionals. The standard was amended by ISO/IEC 27021:2017/Amd 1:2021, which added mapping to ISO/IEC 27001:2013 clauses. It is a supporting standard within the ISO/IEC 27000 series and is distinct from the certifiable ISMS requirements in ISO/IEC 27001 clauses 4 through 10; ISO/IEC 27021 addresses individual professional competence rather than organizational certification, and conformance with it does not itself result in ISMS certification.
Why it matters
Most of the ISO/IEC 27000 series addresses what an organization must do to build and run an information security management system (ISMS). ISO/IEC 27021 fills a different gap: it defines the competence, the business and information security management knowledge and skills, that individuals need to lead or contribute to those ISMS processes. Because the success of an ISMS depends heavily on the people running it, having a recognized reference for practitioner competence helps organizations move beyond ad hoc judgments about who is qualified to establish, implement, maintain, and continually improve their security program.
For organizations pursuing or maintaining ISO/IEC 27001 certification, competent personnel matter directly: ISO/IEC 27001 itself requires organizations to determine and ensure the competence of people whose work affects the ISMS. ISO/IEC 27021 provides a structured articulation of what that competence looks like, which can inform role descriptions, hiring criteria, training curricula, and professional development plans. The 2021 amendment (ISO/IEC 27021:2017/Amd 1:2021) added mapping to ISO/IEC 27001:2013 clauses, which helps practitioners and employers connect specific competencies to the clause-level ISMS requirements.
It is important to understand the limits of the standard. ISO/IEC 27021 addresses individual professional competence rather than organizational conformance, and it does not on its own result in ISMS certification. Meeting its competence descriptions does not certify an organization against ISO/IEC 27001, nor is it a substitute for the certifiable requirements in clauses 4 through 10. Its value is as a supporting reference for building and evaluating the human capability behind an ISMS, not as a certifiable standard in its own right.
Who it's relevant to
Inside ISO/IEC 27021
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27021.