Overview
ISO/IEC 27000:2018 - Information technology - Security techniques - Information security management systems - Overview and vocabulary - provides a concise overview of the ISMS family of standards and the common terminology used across those standards. Applicable to organizations of all types and sizes (commercial, government, not‑for‑profit), ISO/IEC 27000:2018 helps establish a consistent language and conceptual foundation for information security management. The edition includes editorial and structural updates (alignment to the high‑level structure for management systems and updates to Clause 5) while noting that the vocabulary is not exhaustive and does not restrict future definitions within the ISMS family.
Key topics and technical focus
ISO/IEC 27000:2018 focuses on foundational concepts rather than prescriptive controls. Key topics include:
- Definition of ISMS and core principles of an information security management system
- Common terms and definitions used across the ISMS family (overview, information, information security, management, management system)
- Process approach for implementing and operating an ISMS
- Core ISMS lifecycle activities:
- Identifying information security requirements
- Assessing information security risks
- Treating information security risks
- Selecting and implementing controls
- Monitoring, maintaining and improving ISMS effectiveness
- Continual improvement and critical success factors
- Benefits and purpose of the ISMS family of standards, and how ISO/IEC 27000 supports their consistent application
Practical applications and who uses it
ISO/IEC 27000:2018 is a reference and orientation document used by:
- Information security managers and governance teams establishing or aligning an ISMS
- Risk and compliance professionals preparing for ISO/IEC 27001 implementation or certification audits
- Auditors and consultants who need consistent vocabulary and context across the ISO/IEC 27000 series
- Executive stakeholders and board members seeking an accessible overview of ISMS scope, benefits and lifecycle
Practical applications:
- Aligning internal policies and documentation with internationally accepted ISMS terminology
- Preparing for ISO/IEC 27001 implementation, risk assessments (ISO/IEC 27005), and control selection (ISO/IEC 27002)
- Training staff on common information security terms to reduce ambiguity across teams
Related standards
ISO/IEC 27000 is the gateway to the ISMS family, including (not limited to):
ISO/IEC 27000:2018 is ideal as the starting point for organizations pursuing robust information security management, consistent terminology, and alignment with international best practice.