Skip to main content
Category: Standards and Frameworks

ISO/IEC 27032

Also known as: ISO 27032, ISO/IEC 27032:2023, Guidelines for Internet security, Cybersecurity — Guidelines for Internet security
Simply put

ISO/IEC 27032 is an international standard that offers guidance on Internet security and how organizations can address common online threats. Rather than being something an organization gets certified against, it provides recommendations and explanations to help improve security practices. It also clarifies how Internet security relates to related areas such as web security, network security, and cybersecurity.

Formal definition

ISO/IEC 27032 is a guidance document (not a certifiable management system standard) providing recommendations for Internet security. In its 2012 first edition, it was framed around improving the state of cybersecurity and drawing out the unique aspects of that activity and its dependencies on other security domains. The 2023 second edition ('Cybersecurity, Guidelines for Internet security') focuses on addressing Internet security issues and provides guidance for common Internet security threats, and explains the relationship between Internet security, web security, network security, and cybersecurity. Because it is advisory in nature, organizations do not obtain certification against ISO/IEC 27032; it is distinct from the certifiable ISO/IEC 27001 ISMS requirements and functions instead as supporting guidance. Control counts, clause references, and specific threat categories depend on the edition, and practitioners should cite the applicable version.

Why it matters

ISO/IEC 27032 matters because Internet security threats often fall between the boundaries of established security domains, and organizations frequently struggle to understand how web security, network security, and broader cybersecurity fit together. By offering guidance on addressing common Internet security threats and clarifying the relationship between these related areas, the standard helps organizations develop a more coherent view of the risks they face online. This is particularly valuable for teams that need a shared vocabulary and conceptual framework when coordinating security efforts across functions that traditionally operate in silos.

Unlike ISO/IEC 27001, ISO/IEC 27032 is advisory in nature and is not a standard organizations get certified against. Its value lies in supporting and informing security practices rather than in producing a certificate or attestation. Because of this, it typically complements a certifiable management system rather than replacing one, and organizations should not expect it to serve as evidence of compliance in the way an ISO 27001 certificate or a SOC 2 report might.

Practitioners should also note that the guidance has evolved between editions. The 2012 first edition was framed around improving the overall state of cybersecurity and drawing out its unique aspects and dependencies on other security domains, while the 2023 second edition reorients toward Internet security issues specifically. Because the focus, structure, and any threat categorizations depend on the edition, it is important to cite the applicable version when referencing the standard.

Who it's relevant to

Security engineers and architects
Teams designing and operating controls across web, network, and Internet-facing systems can use ISO/IEC 27032 to understand how these domains interrelate and to inform their approach to common Internet security threats. Because the guidance is advisory, it typically supports design decisions rather than dictating mandatory controls.
GRC and compliance professionals
Governance, risk, and compliance practitioners may reference ISO/IEC 27032 as supporting guidance alongside certifiable frameworks. It is important to recognize that organizations do not obtain certification against ISO/IEC 27032, so it should not be presented as certification evidence in the way an ISO/IEC 27001 certificate can be.
Organizations building or maturing an ISMS
Organizations that maintain or are pursuing an ISO/IEC 27001 ISMS can draw on ISO/IEC 27032 as complementary guidance for Internet security topics. It functions as supporting material and is distinct from the certifiable ISMS requirements, so it informs rather than replaces the controls selected through a risk assessment and Statement of Applicability.
Auditors and assessors
Auditors reviewing an organization's Internet security posture may find the standard useful for understanding the boundaries between web, network, and Internet security. Since it is not a certifiable standard, assessors should treat it as guidance and cite the specific edition, as the focus and content differ between the 2012 and 2023 versions.

Inside ISO/IEC 27032

Guidance Standard (Non-Certifiable)
ISO/IEC 27032 is a guidance document providing recommendations for cybersecurity, rather than a management system standard against which an organization is certified. Unlike ISO/IEC 27001, it does not contain certifiable requirements in clauses 4 through 10, so a certification body does not issue an accredited certificate against ISO/IEC 27032.
Cyberspace Security Focus
The standard addresses cybersecurity concerns arising from the interaction of stakeholders in cyberspace, an area that spans domains such as information security, network security, internet security, and critical infrastructure protection. Its scope typically emphasizes threats and collaboration that fall between and across these more established domains.
Stakeholder Collaboration and Information Sharing
A recurring theme in the guidance is coordination among multiple stakeholders and the sharing of information to address cybersecurity threats that no single party controls. The specific mechanisms recommended depend on the organization's context and are advisory rather than mandatory.
Relationship to the Broader ISO/IEC 27000 Family
ISO/IEC 27032 sits within the wider family of information security standards but serves a different purpose from the certifiable ISO/IEC 27001 and the reference control set in ISO/IEC 27002. It is generally used to complement, not replace, an established information security management system.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27032.

Can an organization get certified against ISO/IEC 27032?
No. ISO/IEC 27032 is guidance rather than a requirements standard, so it is not a certifiable standard in the way ISO/IEC 27001 is. Certification against a management system is achieved through ISO/IEC 27001, whose certifiable requirements sit in clauses 4 through 10. ISO/IEC 27032 can inform how an organization approaches certain security topics, but a certification body does not issue a certificate against it. If you need a certifiable outcome, that path typically runs through ISO/IEC 27001.
Is ISO/IEC 27032 just another name for ISO/IEC 27001 focused on the internet?
No. The two are distinct documents with different purposes. ISO/IEC 27001 specifies requirements for an information security management system and is the standard against which accredited certification bodies certify. ISO/IEC 27032 is guidance-oriented and addresses a narrower topical area. Treating them as interchangeable overstates their relationship; ISO/IEC 27032 does not replace or duplicate the ISMS requirements found in ISO/IEC 27001.
How does ISO/IEC 27032 fit alongside an existing ISO/IEC 27001 ISMS?
In most cases, organizations use ISO/IEC 27032 as supplementary guidance that supports decisions made within their ISMS rather than as a governing standard. The ISMS structure and the selection of Annex A reference controls via the Statement of Applicability remain driven by ISO/IEC 27001 and the organization's risk assessment. ISO/IEC 27032 can inform the reasoning behind certain controls, but it does not change which requirements are certifiable. How closely it is used depends on scope and organizational priorities.
Do auditors or certification bodies check compliance with ISO/IEC 27032?
Typically, a certification body assesses conformity against the certifiable requirements of ISO/IEC 27001, not against ISO/IEC 27032, since the latter is guidance. Where an organization references ISO/IEC 27032 in its own documentation, an auditor may consider it as context, but conformity is judged against the applicable standard being certified. Whether and how it is referenced during an assessment depends on the certification body and the defined scope of the engagement.
Should ISO/IEC 27032 guidance be documented in the Statement of Applicability?
The Statement of Applicability under ISO/IEC 27001 addresses the selection and justification of Annex A reference controls, informed by risk assessment. ISO/IEC 27032, being guidance rather than a set of certifiable controls, is not itself an item that the Statement of Applicability is designed to record. Organizations may note supplementary guidance sources in supporting documentation, but the practice varies and is a scoping decision rather than a fixed requirement.
Does adopting ISO/IEC 27032 help satisfy SOC 2 requirements?
Not directly. SOC 2 is an attestation examination performed by a licensed CPA firm and is evaluated against the Trust Services Criteria, with Security (the Common Criteria) being the only required category and the others selected based on scope. ISO/IEC 27032 is separate guidance and is not part of that criteria set. Any influence it has would be indirect, through how it shapes an organization's practices; it does not automatically map to or satisfy SOC 2 criteria, and satisfying one framework does not automatically satisfy another.

Common misconceptions

An organization can be certified against ISO/IEC 27032 the same way it is certified against ISO/IEC 27001.
ISO/IEC 27032 is guidance and does not carry certifiable management system requirements. Accredited certification is associated with ISO/IEC 27001, whose requirements reside in clauses 4 through 10; ISO/IEC 27032 is typically adopted as advisory guidance rather than as the basis for a certificate.
Following ISO/IEC 27032 satisfies SOC 2 or ISO/IEC 27001 obligations.
The frameworks serve distinct purposes. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report, while ISO/IEC 27001 is a certification against a management system standard. Using ISO/IEC 27032 guidance does not automatically satisfy either, and any alignment between them is partial and depends on scope.
ISO/IEC 27032 is interchangeable with ISO/IEC 27002, ISO/IEC 27017, or ISO/IEC 27018.
These are separate documents with different scopes. ISO/IEC 27002 provides reference control guidance, while ISO/IEC 27017 and ISO/IEC 27018 address cloud-related and privacy-related topics. ISO/IEC 27032 focuses on cybersecurity in cyberspace and should not be conflated with them; practitioners should confirm the applicable standard for their specific need.

Best practices

Treat ISO/IEC 27032 as advisory guidance that complements, rather than replaces, a certifiable framework such as an ISO/IEC 27001 management system.
Confirm the exact standard and its purpose before relying on it, since ISO/IEC 27032 does not produce an accredited certificate the way ISO/IEC 27001 does.
Where certification or attestation is the objective, scope the ISO/IEC 27001 ISMS or the SOC 2 examination separately and do not assume ISO/IEC 27032 guidance satisfies those requirements.
Use the standard's emphasis on stakeholder collaboration and information sharing to strengthen coordination on cross-domain cybersecurity threats, tailoring the mechanisms to your organization's context.
Distinguish ISO/IEC 27032 from related documents such as ISO/IEC 27002, ISO/IEC 27017, and ISO/IEC 27018, selecting the standard whose scope matches the specific control or domain in question.
Document how any ISO/IEC 27032 guidance you adopt maps to your existing controls, recognizing that alignment across frameworks is typically partial and depends on scope.