ISO/IEC 27001 Concepts and Terminology
ISO/IEC 27001 is the international standard that specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). Its vocabulary is defined mainly in ISO/IEC 27000, and a Lead Auditor must apply these terms consistently w… ISO/IEC 27001 is the international standard that specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). Its vocabulary is defined mainly in ISO/IEC 27000, and a Lead Auditor must apply these terms consistently when evaluating conformity. An ISMS is a systematic, risk-based set of policies, processes, roles and controls that an organization uses to protect information. The core objective is preserving the CIA triad. Confidentiality means information is not disclosed to unauthorized parties. Integrity means information remains accurate and complete. Availability means information is accessible to authorized users when needed. Key risk terms include the following. An asset is anything of value to the organization, such as data, people, software or facilities. A threat is a potential cause of an unwanted incident. A vulnerability is a weakness that a threat can exploit. Risk is the effect of uncertainty on objectives and is usually expressed as likelihood combined with consequence. A risk owner is the person accountable for managing a particular risk. Risk treatment options are to modify, retain, avoid or share the risk. A control is a measure that modifies risk. The 2022 edition contains 93 Annex A controls grouped into four themes: organizational, people, physical and technological. The Statement of Applicability (SoA) documents which controls are included or excluded, along with the justification for each decision. The standard follows the Harmonized Structure, with Clauses 4 to 10 covering context, leadership, planning, support, operation, performance evaluation and improvement. These clauses reflect the Plan-Do-Check-Act cycle. Other essential terms include interested parties, ISMS scope, documented information, information security event, information security incident, nonconformity and corrective action. Continual improvement is the ongoing effort to enhance ISMS effectiveness. For auditors, ISO 19011 concepts complement these terms. Audit criteria are the requirements used as a reference. Audit evidence is verifiable information. Audit findings are the results of comparing evidence against criteria, which leads to conclusions about conformity and effectiveness.
ISO/IEC 27001 Concepts and Terminology: A Complete Guide for the ISO 27001 Lead Auditor Exam
Introduction
Every ISO/IEC 27001 Lead Auditor needs a firm grip on the concepts and terminology behind an Information Security Management System (ISMS). The standard is written in precise language. Words such as shall, should, risk owner, interested party and nonconformity each have an exact meaning. Misreading one term can lead to a wrong audit finding, a wrong certification decision or a wrong exam answer.
This guide covers four things:
1. Why the topic matters.
2. What the key concepts and terms are.
3. How they fit together in a working ISMS.
4. How to answer exam questions on them with confidence.
1. Why ISO/IEC 27001 Concepts and Terminology Are Important
a) A common language for auditors, auditees and certification bodies
ISO/IEC 27001 is used worldwide. Shared definitions, mainly in ISO/IEC 27000 (Overview and vocabulary), mean an auditor in Germany and an auditee in Singapore understand risk treatment or corrective action the same way.
b) Audit evidence must be judged against precise criteria
An auditor compares objective evidence with audit criteria. If you confuse a correction with a corrective action, or a control with a control objective, your conclusions will be flawed. Accurate terminology underpins credible findings.
c) Requirements versus guidance
Key distinctions:
- Shall = a requirement. Only these clauses are auditable for conformity.
- Should = a recommendation.
- May = a permission.
- Can = a possibility or capability.
Lead auditors must never raise a nonconformity against a should statement from guidance documents such as ISO/IEC 27002.
d) Foundation for every other exam domain
Audit planning, conducting audits, reporting and follow-up all depend on these concepts. Exam questions in every domain assume you know them.
e) Professional credibility
Using terms correctly in opening meetings, interviews, reports and closing meetings shows competence. That competence is required under ISO/IEC 17021-1 and ISO 19011.
2. What It Is: Core Concepts and Terminology
2.1 The Family of Standards
- ISO/IEC 27000: Overview and vocabulary. This is the normative reference for terms used in ISO/IEC 27001.
- ISO/IEC 27001:2022: The requirements standard. It is the only certifiable standard in the family. Clauses 4 to 10 contain requirements, and Annex A lists 93 reference controls.
- ISO/IEC 27002:2022: Guidance on implementing information security controls. It is not certifiable.
- ISO/IEC 27003: ISMS implementation guidance.
- ISO/IEC 27004: Monitoring, measurement, analysis and evaluation.
- ISO/IEC 27005: Information security risk management guidance.
- ISO/IEC 27006: Requirements for bodies providing audit and certification of ISMS.
- ISO/IEC 27007: Guidelines for ISMS auditing. It complements ISO 19011.
- ISO 19011: Guidelines for auditing management systems.
- ISO/IEC 17021-1: Requirements for certification bodies.
2.2 The Harmonized Structure (formerly Annex SL / High Level Structure)
ISO/IEC 27001 follows the same 10-clause structure as ISO 9001, ISO 14001 and ISO 45001:
- Clause 1: Scope
- Clause 2: Normative references
- Clause 3: Terms and definitions
- Clause 4: Context of the organization
- Clause 5: Leadership
- Clause 6: Planning
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance evaluation
- Clause 10: Improvement
Clauses 4 to 10 are mandatory. An organization cannot exclude any of them.
2.3 Fundamental Information Security Concepts
- Information: An asset that has value to the organization and needs suitable protection. It can be printed, electronic, spoken or known by people.
- Information security: Preservation of the confidentiality, integrity and availability (the CIA triad) of information. Other properties may also be involved, such as authenticity, accountability, non-repudiation and reliability.
- Confidentiality: Information is not made available or disclosed to unauthorized individuals, entities or processes.
- Integrity: The property of accuracy and completeness.
- Availability: Accessible and usable on demand by an authorized entity.
- Authenticity: An entity is what it claims to be.
- Non-repudiation: The ability to prove that a claimed event or action occurred, and which entities originated it.
2.4 Management System Concepts
- Management system: A set of interrelated or interacting elements of an organization used to establish policies, objectives and processes to achieve those objectives.
- ISMS: The part of the overall management system, based on a risk approach, that establishes, implements, operates, monitors, reviews, maintains and improves information security.
- Top management: The person or group who directs and controls an organization at the highest level.
- Interested party (stakeholder): A person or organization that can affect, be affected by, or perceive itself to be affected by a decision or activity.
- Context of the organization: Internal and external issues relevant to the organization's purpose that affect its ability to achieve the intended outcomes of the ISMS (Clause 4.1).
- Scope: The boundaries and applicability of the ISMS (Clause 4.3). It must be available as documented information.
- Policy: The intentions and direction of an organization, as formally expressed by top management.
- Objective: A result to be achieved. Information security objectives must be measurable where practicable (Clause 6.2).
- Process: A set of interrelated or interacting activities that uses or transforms inputs to deliver a result.
- Outsource: An arrangement where an external organization performs part of an organization's function or process.
- Competence: The ability to apply knowledge and skills to achieve intended results.
- Documented information: Information required to be controlled and maintained, together with the medium containing it.
- Maintain documented information broadly corresponds to the former term documents.
- Retain documented information broadly corresponds to the former term records.
2.5 Risk Concepts
- Risk: The effect of uncertainty on objectives. The effect can be positive or negative.
- Information security risk: Associated with the potential that threats will exploit vulnerabilities of an information asset and cause harm.
- Threat: A potential cause of an unwanted incident.
- Vulnerability: A weakness of an asset or control that can be exploited by one or more threats.
- Likelihood: The chance of something happening.
- Consequence: The outcome of an event affecting objectives.
- Level of risk: The magnitude of a risk, expressed as a combination of consequence and likelihood.
- Risk owner: The person or entity with the accountability and authority to manage a risk. Risk owners approve the risk treatment plan and accept residual risks (Clause 6.1.3 f).
- Risk assessment: The overall process of risk identification, risk analysis and risk evaluation.
- Risk treatment: The process to modify risk. Common options:
- Avoid
- Modify/reduce (apply controls)
- Share/transfer
- Retain/accept
- Residual risk: The risk remaining after risk treatment.
- Risk acceptance criteria: The criteria for deciding which risks are acceptable (Clause 6.1.2 a).
2.6 Control Concepts
- Control: A measure that maintains and/or modifies risk. Examples include policies, procedures, technical measures and organizational structures.
- Control objective: A statement describing what is to be achieved as a result of implementing controls.
- Statement of Applicability (SoA): Required by Clause 6.1.3 d. It must contain:
- the necessary controls,
- the justification for their inclusion,
- whether they are implemented,
- the justification for excluding any Annex A controls.
- Annex A (2022): 93 controls in four themes:
- Organizational (37)
- People (8)
- Physical (14)
- Technological (34)
Annex A is a reference list. Organizations may use controls from other sources, but they must compare their chosen controls against Annex A to make sure nothing necessary is omitted.
2.7 Performance and Improvement Concepts
- Monitoring: Determining the status of a system, process or activity.
- Measurement: A process to determine a value.
- Effectiveness: The extent to which planned activities are realized and planned results achieved.
- Conformity: Fulfilment of a requirement.
- Nonconformity: Non-fulfilment of a requirement.
- Correction: Action to eliminate a detected nonconformity. This is the immediate fix.
- Corrective action: Action to eliminate the cause of a nonconformity and to prevent recurrence. This addresses the root cause.
- Continual improvement: A recurring activity to enhance performance (Clause 10.1).
- Information security event: An identified occurrence indicating a possible breach of security or failure of controls.
- Information security incident: One or more unwanted or unexpected events with a significant probability of compromising business operations and threatening information security.
2.8 Audit Concepts (ISO 19011 / ISO/IEC 17021-1)
- Audit: A systematic, independent and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled.
- Audit criteria: The set of requirements used as a reference. Examples include ISO/IEC 27001, policies, contracts and legal requirements.
- Objective evidence: Data supporting the existence or verity of something. It is verifiable.
- Audit evidence: Records, statements of fact or other information relevant to the audit criteria and verifiable.
- Audit findings: Results of evaluating audit evidence against audit criteria. Findings may show conformity, nonconformity or opportunities for improvement.
- Audit conclusion: The outcome of an audit, after considering the audit objectives and all findings.
- Audit types by party:
- First-party (internal)
- Second-party (customer or supplier)
- Third-party (certification)
- Certification audit stages:
- Stage 1: documentation review and readiness.
- Stage 2: implementation and effectiveness.
- Followed by surveillance audits and a recertification audit on a three-year cycle.
- Major nonconformity: Affects the capability of the management system to achieve intended results. Examples include the absence or total breakdown of a required process.
- Minor nonconformity: Does not affect that capability. It is typically an isolated lapse.
3. How It Works: The Concepts in Action
3.1 The PDCA Logic
The 2022 edition no longer names PDCA explicitly, but the clause structure follows it:
- Plan: Clauses 4, 5, 6 and 7. Understand the context, secure leadership commitment, assess risks, set objectives and provide resources.
- Do: Clause 8. Operate processes, perform risk assessments at planned intervals, implement the risk treatment plan and manage change.
- Check: Clause 9. Monitor and measure, run internal audits and hold management reviews.
- Act: Clause 10. Address nonconformities with corrections and corrective actions, and improve continually.
3.2 The Risk-Based Flow
1. Determine the context (4.1) and the needs of interested parties (4.2). The 2022 edition adds identifying which of those needs are addressed through the ISMS.
2. Define the scope (4.3).
3. Top management sets the information security policy and assigns roles (5.1 to 5.3).
4. Define risk criteria, then identify, analyze and evaluate risks and assign risk owners (6.1.2).
5. Select treatment options and determine controls, comparing them with Annex A (6.1.3).
6. Produce the SoA and the risk treatment plan. Risk owners approve the plan and accept residual risk.
7. Set measurable information security objectives (6.2) and plan changes (6.3, new in 2022).
8. Provide resources, competence, awareness, communication and documented information (Clause 7).
9. Operate and implement (Clause 8).
10. Evaluate through monitoring, internal audit and management review (Clause 9).
11. Improve through corrective action and continual improvement (Clause 10).
3.3 Example Linking the Terms
A company identifies that customer data (an asset) in a cloud database is at risk.
- The threat is an external attacker.
- The vulnerability is weak passwords.
- High likelihood combined with severe consequence gives a high level of risk, which exceeds the risk acceptance criteria.
- The risk owner, the Head of IT, chooses to modify the risk by implementing multi-factor authentication (Annex A 8.5, Secure authentication).
- This is recorded in the SoA and the risk treatment plan.
- The residual risk is accepted by the risk owner.
During an internal audit, the auditor finds that 10% of admin accounts lack MFA. That is a nonconformity.
- The correction is enabling MFA on those accounts.
- The corrective action is fixing the onboarding procedure that allowed the gap, after root-cause analysis.
- Effectiveness is later verified.
3.4 Key 2022 Changes to Know
- Annex A was restructured from 114 controls in 14 domains to 93 controls in 4 themes.
- There are 11 new controls:
- Threat intelligence
- Information security for use of cloud services
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
- Clause 6.3, Planning of changes, was added.
- Clause 4.2 now asks which interested party requirements are addressed through the ISMS.
- Clause 4.4 adds explicit reference to the processes needed and their interactions.
- The transition deadline for 2013 certificates was 31 October 2025.
4. How to Answer Exam Questions on ISO/IEC 27001 Concepts and Terminology
4.1 Common Question Formats
- Definition questions: "Which term describes the effect of uncertainty on objectives?"
- Distinction questions: "What is the difference between a correction and a corrective action?"
- Scenario questions: A situation is described, and you must identify the concept, clause or correct audit response.
- Clause-mapping questions: "Which clause requires the organization to determine interested parties?" (Answer: 4.2.)
- Essay or case-study questions: Common in PECB and similar exams. You justify a finding using the correct terms and clause references.
4.2 A Step-by-Step Method
1. Read the stem twice. Underline keywords such as shall, cause, immediate, accountable, remaining and weakness.
2. Identify the concept being tested. Ask whether it concerns risk, control, audit, documentation or improvement.
3. Recall the ISO/IEC 27000 definition, not everyday usage.
4. Eliminate distractors. These are often near-synonyms, for example threat versus vulnerability, or policy versus procedure.
5. Map to a clause where relevant, so you can justify the answer.
6. Check the auditor's perspective. An auditor evaluates and reports. An auditor does not implement, advise on solutions or design controls, because that would compromise impartiality.
Exam Tips: Answering Questions on ISO/IEC 27001 Concepts and Terminology
Tip 1: Use the official definitions. Exams test ISO/IEC 27000 wording. For example, risk is the effect of uncertainty on objectives, not simply the chance of loss.
Tip 2: Master the CIA triad.
- Unauthorized disclosure affects confidentiality.
- Unauthorized modification or corruption affects integrity.
- Downtime or inaccessibility affects availability.
Scenario questions often hinge on this.
Tip 3: Threat vs. vulnerability vs. risk.
- A threat is the potential cause (a hacker, fire or flood).
- A vulnerability is the weakness (an unpatched server or no fire suppression).
- Risk is the combination of likelihood and consequence.
Tip 4: Correction vs. corrective action vs. preventive action.
- Correction fixes the symptom.
- Corrective action removes the root cause to prevent recurrence.
- Preventive action is no longer a separate clause. It is embedded in risk-based thinking (Clause 6.1).
Tip 5: Shall = requirement.
- Only shall statements in ISO/IEC 27001 clauses 4 to 10, plus controls the organization declares applicable in its SoA, can lead to nonconformities.
- ISO/IEC 27002 guidance is not an audit criterion unless the organization adopts it.
Tip 6: Clauses 4 to 10 cannot be excluded.
- Only Annex A controls can be excluded, and each exclusion needs a justification in the SoA.
- Any answer suggesting an organization can exclude Clause 9.2 (internal audit) is wrong.
Tip 7: Know who does what.
- Top management establishes the policy, ensures resources, assigns responsibilities and conducts management reviews.
- Risk owners approve risk treatment plans and accept residual risk.
- Auditors collect and evaluate evidence. They do not implement.
Tip 8: Documented information traps.
- Mandatory documented information includes:
- scope (4.3)
- information security policy (5.2)
- risk assessment process (6.1.2)
- risk treatment process (6.1.3)
- SoA (6.1.3 d)
- information security objectives (6.2)
- evidence of competence (7.2)
- operational planning information (8.1)
- risk assessment results (8.2)
- risk treatment results (8.3)
- monitoring and measurement results (9.1)
- audit programme and results (9.2)
- management review results (9.3)
- nonconformities and corrective actions (10.2)
- Watch for distractors that claim a documented procedure is mandatory for everything. It is not.
Tip 9: Event vs. incident. Not every event is an incident. An incident is an event, or a series of events, with a significant probability of compromising operations or security.
Tip 10: Major vs. minor nonconformity.
- Major means the absence or systemic breakdown of a requirement, or a doubt about the ISMS achieving its intended outcomes.
- Minor means an isolated lapse.
- An opportunity for improvement (OFI) is not a nonconformity.
Tip 11: Know the 2022 numbers and structure.
- 93 controls in 4 themes.
- Clause 6.3 is new.
- Control attributes come from ISO/IEC 27002:2022, are informative, and are not auditable on their own.
Tip 12: Annex A is not exhaustive. Organizations may add controls from other sources (Clause 6.1.3 c, Note). Answers claiming Annex A must be implemented in full are wrong.
Tip 13: In essay questions, structure your answer.
- State the requirement, with its clause number.
- Describe the evidence observed.
- State the gap, if any.
- Classify the finding.
- Use precise terms, for example: "The organization has not retained documented information as evidence of competence, contrary to ISO/IEC 27001:2022 Clause 7.2 d."
Tip 14: Avoid absolute words in options. Choices containing always, never or all are often wrong unless they reflect a true shall requirement, such as "all clauses 4 to 10 are mandatory."
Tip 15: Think like a lead auditor. When a scenario asks what the auditor should do, choose the option that:
- is evidence-based,
- maintains impartiality,
- follows ISO 19011 principles: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach and risk-based approach.
Tip 16: Memorize with mnemonics.
- CIA for the security properties.
- AMTA (Avoid, Modify, Transfer, Accept) for risk treatment.
- C-L-P-S-O-P-I (Context, Leadership, Planning, Support, Operation, Performance, Improvement) for clauses 4 to 10.
5. Quick Self-Check Practice
1. A backup server fails and users cannot access files for six hours. Which property is affected? Answer: Availability.
2. An auditor finds that an employee shared a password. IT immediately resets it. What is this? Answer: A correction. A corrective action would address why the sharing happened, for example through awareness training or process redesign.
3. Who accepts residual information security risks? Answer: The risk owners (Clause 6.1.3 f).
4. Can an organization exclude Clause 7.5 because it is a small company? Answer: No. Clauses 4 to 10 cannot be excluded, though the extent of documentation may vary with organization size.
5. Which document lists the necessary controls and justifies the inclusion or exclusion of Annex A controls? Answer: The Statement of Applicability.
Conclusion
ISO/IEC 27001 concepts and terminology are the vocabulary of the whole ISMS and of auditing itself. Learn the ISO/IEC 27000 definitions, the harmonized clause structure, the risk-based logic and the audit terms from ISO 19011 and ISO/IEC 17021-1. With these, you can interpret requirements correctly, evaluate evidence objectively and answer exam questions precisely. In the exam, read carefully, think like an impartial auditor, anchor each answer to a definition or clause, and do not let near-synonym distractors mislead you.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!