ISO/IEC 27000:2018
Information technology — Security techniques — Information security management systems — Overview and vocabulary
Information technology — Security techniques — Information security management systems — Overview and vocabulary
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 27
- Дата публикации:
- 7 февраля 2018 г.
- Издание:
- ISO/IEC IS 27000 edition 5 version 1
- ICS:
- 01.040.35
ISO/IEC 27000:2018 provides the overview of information security management systems (ISMS). It also provides terms and definitions commonly used in the ISMS family of standards. This document is applicable to all types and sizes of organization (e.g. commercial enterprises, government agencies, not-for-profit organizations). The terms and definitions provided in this document - cover commonly used terms and definitions in the ISMS family of standards; - do not cover all terms and definitions applied within the ISMS family of standards; and - do not limit the ISMS family of standards in defining new terms for use.
Abstract
Overview
ISO/IEC 27000:2018 - Information technology - Security techniques - Information security management systems - Overview and vocabulary - provides a concise overview of the ISMS family of standards and the common terminology used across those standards. Applicable to organizations of all types and sizes (commercial, government, not‑for‑profit), ISO/IEC 27000:2018 helps establish a consistent language and conceptual foundation for information security management. The edition includes editorial and structural updates (alignment to the high‑level structure for management systems and updates to Clause 5) while noting that the vocabulary is not exhaustive and does not restrict future definitions within the ISMS family.
Key topics and technical focus
ISO/IEC 27000:2018 focuses on foundational concepts rather than prescriptive controls. Key topics include:
- Definition of ISMS and core principles of an information security management system
- Common terms and definitions used across the ISMS family (overview, information, information security, management, management system)
- Process approach for implementing and operating an ISMS
- Core ISMS lifecycle activities:
- Identifying information security requirements
- Assessing information security risks
- Treating information security risks
- Selecting and implementing controls
- Monitoring, maintaining and improving ISMS effectiveness
- Continual improvement and critical success factors
- Benefits and purpose of the ISMS family of standards, and how ISO/IEC 27000 supports their consistent application
Practical applications and who uses it
ISO/IEC 27000:2018 is a reference and orientation document used by:
- Information security managers and governance teams establishing or aligning an ISMS
- Risk and compliance professionals preparing for ISO/IEC 27001 implementation or certification audits
- Auditors and consultants who need consistent vocabulary and context across the ISO/IEC 27000 series
- Executive stakeholders and board members seeking an accessible overview of ISMS scope, benefits and lifecycle
Practical applications:
- Aligning internal policies and documentation with internationally accepted ISMS terminology
- Preparing for ISO/IEC 27001 implementation, risk assessments (ISO/IEC 27005), and control selection (ISO/IEC 27002)
- Training staff on common information security terms to reduce ambiguity across teams
Related standards
ISO/IEC 27000 is the gateway to the ISMS family, including (not limited to):
- ISO/IEC 27001 - Requirements for an ISMS
- ISO/IEC 27002 - Code of practice for information security controls
- ISO/IEC 27003 - Implementation guidance
- ISO/IEC 27004 - Measurement
- ISO/IEC 27005 - Risk management
- ISO/IEC 27006 - Requirements for bodies providing audit and certification
ISO/IEC 27000:2018 is ideal as the starting point for organizations pursuing robust information security management, consistent terminology, and alignment with international best practice.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27000:2018
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27000:2014
ОтменёнInformation technology — Security techniques — Information security management systems — Overview and vocabul…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
BS EN ISO/IEC 27005:2024
ДействующийInformation security, cybersecurity and privacy protection. Guidance on managing information security risks.
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…