Overview
ISO/IEC TS 27022:2021 - Information technology - Guidance on information security management system processes - is a Technical Specification that provides a process reference model (PRM) for information security management systems (ISMS). Published in 2021, the PRM in ISO/IEC TS 27022:2021 is aligned with the ISO/IEC 27000 family and meets the criteria of ISO/IEC 33004 for process reference models. It is intended as operational guidance to help organizations implement the process approach of ISO/IEC 27001 and to complement the requirements-focused guidance of ISO/IEC 27003.
Key topics
- Process Reference Model (PRM): A generic architecture of ISMS processes described by purpose, inputs/results, activities, flowcharts and references.
- Process categories: Management, core and support processes tailored to ISMS operation.
- Core ISMS processes (examples):
- Security policy management
- Requirements management (interested parties, legal/regulatory/contractual needs)
- Information security risk assessment and risk treatment
- Security implementation management
- Information security incident management
- Change management and internal audit
- Performance evaluation and continuous improvement
- Support processes: Records control, resource management, communication, customer relationship management.
- Governance alignment: Interface between information security governance and ISMS operations to ensure organizational objectives are met.
- Guidance characteristics: Describes process purpose and results; does not add certification requirements and must be tailored to organizational context. Includes Annex A on conformity with ISO/IEC 33004.
Applications
- Use ISO/IEC TS 27022:2021 to:
- Translate ISO/IEC 27001 requirements into operational ISMS processes.
- Design, implement and operate ISMS process flows and handoffs.
- Define inputs/outputs, responsibilities and process maturity needs.
- Integrate ISMS processes into an Integrated Management System (IMS).
- Practical outputs include prioritized risk lists with owners, risk treatment plans, control implementation plans, and documented process flowcharts supporting repeatable ISMS operations.
Who should use this standard
- Information security managers and ISMS implementers
- Risk and compliance teams seeking process-based ISMS operation
- Internal auditors and process owners mapping ISO/IEC 27001 requirements to operational workflows
- Consultants designing ISMS process architectures or integrating security into broader management systems
Related standards
Keywords: ISO/IEC TS 27022:2021, ISMS processes, process reference model, information security management, ISO/IEC 27001, risk assessment, incident management, security policy management.