Overview
ISO/IEC 27021:2017 is an international standard developed by ISO and IEC, focusing on the competence requirements for professionals working with Information Security Management Systems (ISMS). This standard provides a clear framework for the necessary skills, knowledge, and abilities required for professionals who are responsible for establishing, implementing, maintaining, and continually improving ISMS processes in alignment with ISO/IEC 27001.
The document is beneficial for organizations seeking to ensure their ISMS professionals meet globally recognized competence criteria, as well as for individuals aiming to validate or develop their skills in information security management.
Key Topics
ISO/IEC 27021:2017 outlines two primary competence areas:
- Business Management Competence: Skills and knowledge necessary to align security objectives with business goals, including leadership, communication, process and resource management, risk management, team management, and supplier relationships.
- Information Security Competence: Technical and managerial information security skills, including governance, planning, operations, support (awareness and documentation), evaluation, and improvement of ISMS processes.
Key areas detailed in the standard include:
- Leadership and communication strategies for ISMS implementation
- Understanding business strategy and integrating information security
- Managing organizational culture and stakeholder expectations
- Risk management as it applies to information security
- Resource and project management specific to ISMS
- Criteria for information security governance, planning, operations, and continual improvement
- Documentation and awareness training to promote a security-positive culture
Applications
ISO/IEC 27021:2017 can be used by:
- Organizations: To define recruitment, training, and development criteria for ISMS-related roles, ensuring staff consistently meet international competence standards.
- Certification Bodies: As a basis for developing certification schemes for ISMS professionals, establishing a standardized body of knowledge for exams and assessments.
- Educational Institutions: To align curricula for information security management education and training with recognized industry requirements.
- ISMS Professionals: For self-assessment, career planning, or to identify areas requiring further development to maintain or enhance their ISMS skills.
- Consultancies: When developing or supporting ISMS implementations, ensuring that personnel are equipped with the necessary competence.
By applying ISO/IEC 27021:2017, organizations not only support compliance with ISO/IEC 27001 but also foster a culture of continual improvement and risk-aware information security management.
Related Standards
To provide comprehensive support for information security management, ISO/IEC 27021:2017 should be used in combination with several related standards:
- ISO/IEC 27001: Requirements for establishing, implementing, maintaining, and continually improving an ISMS.
- ISO/IEC 27000: Overview and vocabulary for information security management systems.
- ISO/IEC 27005: Guidelines for information security risk management.
- ISO 31000: Risk management principles and guidelines applicable to all types of organizations.
- ISO/IEC 27014: Information security governance guidelines.
Practical Value
Implementing ISO/IEC 27021:2017 helps organizations:
- Ensure information security professionals have verifiable competence
- Reduce organizational risk by aligning ISMS functions with best-practice competence frameworks
- Promote efficient ISMS processes that support business objectives
- Enhance credibility in the marketplace through adherence to recognized international standards
- Support ongoing professional development and continual improvement within ISMS roles
Through the application of this standard, stakeholders achieve assurance that their ISMS efforts are supported by qualified professionals, contributing to robust and effective information security management.