Skip to main content
Category: Governance and Roles

ISO/IEC 27021

Also known as: ISO/IEC 27021:2017, ISO 27021
Simply put

ISO/IEC 27021 is an international standard that describes the skills and knowledge a professional should have to lead or work on an organization's information security management system (ISMS). Rather than setting requirements for the security program itself, it defines what makes someone competent to run one. It is used to guide training, hiring, and professional development for ISMS practitioners.

Formal definition

ISO/IEC 27021:2017 specifies the competence requirements for information security management systems professionals who lead or are involved in establishing, implementing, maintaining, and continually improving one or more ISMS processes as defined in the ISO/IEC 27001 family of standards. It articulates the business and information security management knowledge and skills expected of such professionals. The standard was amended by ISO/IEC 27021:2017/Amd 1:2021, which added mapping to ISO/IEC 27001:2013 clauses. It is a supporting standard within the ISO/IEC 27000 series and is distinct from the certifiable ISMS requirements in ISO/IEC 27001 clauses 4 through 10; ISO/IEC 27021 addresses individual professional competence rather than organizational certification, and conformance with it does not itself result in ISMS certification.

Why it matters

Most of the ISO/IEC 27000 series addresses what an organization must do to build and run an information security management system (ISMS). ISO/IEC 27021 fills a different gap: it defines the competence, the business and information security management knowledge and skills, that individuals need to lead or contribute to those ISMS processes. Because the success of an ISMS depends heavily on the people running it, having a recognized reference for practitioner competence helps organizations move beyond ad hoc judgments about who is qualified to establish, implement, maintain, and continually improve their security program.

For organizations pursuing or maintaining ISO/IEC 27001 certification, competent personnel matter directly: ISO/IEC 27001 itself requires organizations to determine and ensure the competence of people whose work affects the ISMS. ISO/IEC 27021 provides a structured articulation of what that competence looks like, which can inform role descriptions, hiring criteria, training curricula, and professional development plans. The 2021 amendment (ISO/IEC 27021:2017/Amd 1:2021) added mapping to ISO/IEC 27001:2013 clauses, which helps practitioners and employers connect specific competencies to the clause-level ISMS requirements.

It is important to understand the limits of the standard. ISO/IEC 27021 addresses individual professional competence rather than organizational conformance, and it does not on its own result in ISMS certification. Meeting its competence descriptions does not certify an organization against ISO/IEC 27001, nor is it a substitute for the certifiable requirements in clauses 4 through 10. Its value is as a supporting reference for building and evaluating the human capability behind an ISMS, not as a certifiable standard in its own right.

Who it's relevant to

ISMS Managers and Security Leaders
Professionals responsible for leading or overseeing an ISMS can use ISO/IEC 27021 as a benchmark for the business and information security management knowledge and skills expected in their role. It helps clarify competence expectations for those establishing, implementing, maintaining, and continually improving ISMS processes.
Hiring Managers and HR in Security Functions
Those responsible for recruiting and developing security staff can draw on the standard's competence descriptions to inform job descriptions, hiring criteria, and evaluation of candidates for ISMS-related roles, supporting more consistent judgments about qualification.
Training Providers and Professional Development Planners
Organizations and individuals designing training curricula or career development paths for ISMS practitioners can use ISO/IEC 27021 as a reference for the knowledge and skill areas to cover, with the 2021 amendment's mapping to ISO/IEC 27001:2013 clauses helping align learning with specific ISMS requirements.
Organizations Pursuing or Maintaining ISO/IEC 27001 Certification
Because ISO/IEC 27001 requires organizations to ensure the competence of people affecting the ISMS, teams working toward or sustaining certification can use ISO/IEC 27021 to help demonstrate and structure that competence, while recognizing it is a supporting standard and does not itself confer certification.

Inside ISO/IEC 27021

Competence requirements for ISMS professionals
ISO/IEC 27021 specifies the competence requirements for professionals who establish, implement, maintain, and continually improve an information security management system (ISMS) as defined by ISO/IEC 27001. It provides a reference for the knowledge and skills expected of such individuals rather than certifying an organization.
Business and management knowledge areas
The standard identifies broader business, leadership, and management competences that support ISMS work, recognizing that effective information security management depends on more than purely technical expertise. The specific breadth of these areas depends on the role and how the guidance is applied.
Information security-specific knowledge and skills
It addresses domain-specific competences relating to information security, aligned with the ISMS requirements found in clauses 4 through 10 of ISO/IEC 27001 and the reference controls informed by Annex A. It is a competence guidance standard and does not itself add certifiable ISMS requirements.
Use as a benchmark rather than a certification scheme
ISO/IEC 27021 is typically used as a benchmark for developing training, defining role requirements, or assessing individual capability. It is guidance for personnel competence and is distinct from the organizational ISO/IEC 27001 certification issued by an accredited certification body.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27021.

Is ISO/IEC 27021 a certification you can obtain for your organization?
No. ISO/IEC 27021 addresses the competence requirements for information security management system (ISMS) professionals rather than serving as an organizational certification. It is not the standard against which an organization's ISMS is certified; that role belongs to ISO/IEC 27001, whose certifiable requirements sit in clauses 4 through 10. ISO/IEC 27021 informs the knowledge and skills expected of individuals who work with an ISMS, and any related credentialing typically applies to people rather than to organizations.
Does following ISO/IEC 27021 make an organization compliant with ISO/IEC 27001?
No. ISO/IEC 27021 is a competence-focused standard for ISMS professionals and does not, on its own, establish organizational conformity with ISO/IEC 27001. Certification against ISO/IEC 27001 depends on implementing the ISMS requirements in clauses 4 through 10, selecting reference controls via a Statement of Applicability informed by risk assessment, and undergoing assessment by an accredited certification body for a defined scope. ISO/IEC 27021 can help ensure that the people involved have relevant competence, but it does not substitute for the certification process or its requirements.
How might ISO/IEC 27021 be used when building an ISMS team?
In most engagements, ISO/IEC 27021 can serve as a reference for defining the competence expectations of individuals in ISMS-related roles. Organizations may use it to inform role descriptions, hiring criteria, and professional development plans so that the people supporting the ISMS have relevant knowledge and skills. How it is applied typically depends on the organization's scope, resourcing, and internal governance decisions rather than any single mandated approach.
How does ISO/IEC 27021 relate to the competence requirements already in ISO/IEC 27001?
ISO/IEC 27001 includes requirements around competence and awareness as part of the ISMS requirements in its clauses, but it does not itself enumerate a detailed competence profile for ISMS professionals. ISO/IEC 27021 can provide more granular guidance on the knowledge and skills expected of such individuals, which organizations may draw on when demonstrating that competence requirements are being met. The precise interplay depends on how an organization interprets and implements its ISMS obligations.
Can ISO/IEC 27021 help prepare for a certification audit?
It can play a supporting role. Depending on scope, aligning the competence of ISMS personnel with the expectations described in ISO/IEC 27021 may help an organization demonstrate that appropriately skilled people manage and operate the ISMS. However, certification audits assess the ISMS against ISO/IEC 27001's requirements and the selected reference controls, so ISO/IEC 27021 is best viewed as one input to readiness rather than a determinant of the audit outcome.
Is ISO/IEC 27021 relevant to SOC 2 engagements?
ISO/IEC 27021 sits within the ISO/IEC 27000 family and is oriented toward ISMS professional competence, so it is not part of the SOC 2 framework. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA's SSAE 18 standard and evaluates controls against the Trust Services Criteria. While personnel competence can matter in any control environment, ISO/IEC 27021 is not referenced by or required for a SOC 2 report, and mapping between the ISO and SOC 2 ecosystems is at best partial.

Common misconceptions

Holding or aligning to ISO/IEC 27021 means an organization is ISO/IEC 27001 certified.
ISO/IEC 27021 concerns the competence of individual ISMS professionals, not organizational certification. ISO/IEC 27001 certification of an ISMS is a separate outcome issued by an accredited certification body against the defined scope of the management system, and personal competence guidance does not confer it.
ISO/IEC 27021 adds mandatory controls or requirements to an ISMS.
It is a competence guidance standard and does not create additional certifiable ISMS requirements. The certifiable requirements remain in clauses 4 through 10 of ISO/IEC 27001, with reference controls selected via a Statement of Applicability informed by risk assessment.
ISO/IEC 27021 is interchangeable with SOC 2 competence expectations.
SOC 2 is an AICPA attestation examination performed by a licensed CPA firm and does not define a personnel competence standard in this manner. Mapping between ISO/IEC frameworks and SOC 2 is at best partial, and competence guidance for one does not automatically satisfy the other.

Best practices

Use ISO/IEC 27021 as a reference to define role descriptions and competence expectations for staff responsible for the ISMS, adapting the guidance to your organization's scope rather than treating it as a fixed rulebook.
Keep the distinction clear between individual competence (ISO/IEC 27021) and organizational certification (ISO/IEC 27001), and communicate this distinction to stakeholders who may confuse the two.
Map identified competence areas back to the ISMS requirements in clauses 4 through 10 of ISO/IEC 27001 so that personnel capabilities support the actual management system rather than abstract skill lists.
Use the competence benchmark to structure training and professional development plans, revisiting them as roles and the ISMS scope evolve.
When citing standard editions or control structures alongside competence planning, specify the version referenced, since details such as Annex A control counts differ between the 2013 and 2022 revisions of ISO/IEC 27001.
Avoid assuming that competence alignment satisfies unrelated frameworks; treat any cross-mapping to SOC 2 or other ISO standards as partial and validate requirements independently.