The ISO/IEC 27000 Family of Standards
The ISO/IEC 27000 family is a series of international standards, published jointly by ISO and IEC, that provides a structured framework for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). For a Lead Auditor, it is essential to know… The ISO/IEC 27000 family is a series of international standards, published jointly by ISO and IEC, that provides a structured framework for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). For a Lead Auditor, it is essential to know which standards contain auditable requirements and which only offer guidance. ISO/IEC 27000 provides the overview and vocabulary for the whole family. It defines key terms such as information security, risk, control, nonconformity and continual improvement, which gives auditors and auditees a common language. ISO/IEC 27001 is the core standard and the only one in the family against which organizations can be certified. It sets out mandatory requirements in Clauses 4 to 10: context of the organization, leadership, planning, support, operation, performance evaluation and improvement. These follow the Harmonized Structure shared with other management system standards such as ISO 9001. Its Annex A lists reference controls. The 2022 edition contains 93 controls grouped into four themes: organizational, people, physical and technological. ISO/IEC 27002 gives detailed implementation guidance for the Annex A controls, but it is not certifiable. Other supporting guidance standards include ISO/IEC 27003 on ISMS implementation, ISO/IEC 27004 on monitoring, measurement, analysis and evaluation, and ISO/IEC 27005 on information security risk management. Several standards address certification and auditing. ISO/IEC 27006 sets requirements for bodies that audit and certify ISMSs. ISO/IEC 27007 provides guidance on auditing an ISMS, building on ISO 19011. ISO/IEC TS 27008 covers the assessment of information security controls. Sector-specific standards extend the framework to particular contexts. Examples include ISO/IEC 27017 for cloud security, ISO/IEC 27018 for protecting personal data in public clouds, ISO/IEC 27019 for the energy sector, and ISO/IEC 27701 for privacy information management. Understanding this family allows auditors to separate normative requirements from informative guidance, so that audit findings are based on objective criteria.
The ISO/IEC 27000 Family of Standards: A Complete Guide for ISO 27001 Lead Auditor Candidates
Introduction
The ISO/IEC 27000 family, often called the ISMS family of standards, is a set of international standards published jointly by ISO and IEC. They help organizations of any size or sector establish, implement, maintain and continually improve an Information Security Management System (ISMS).
For a Lead Auditor candidate, knowing this family is a core part of the domain Fundamental principles and concepts of an ISMS. You must know which standard does what, which ones are requirements and which are guidance, and which one an auditor actually audits against.
Why It Is Important
1. It defines the audit criteria. Certification audits are performed against ISO/IEC 27001, the only standard in the family against which an organization's ISMS is certified. The others support it. An auditor who confuses requirements with guidance may raise invalid nonconformities.
2. It creates a common language. ISO/IEC 27000 provides the vocabulary used across the family. Terms such as risk, control, nonconformity, information security and top management have precise meanings that appear in exam questions and audit reports.
3. It governs the audit process itself. ISO/IEC 27006 sets requirements for certification bodies, and ISO/IEC 27007 gives ISMS-specific auditing guidance that builds on ISO 19011.
4. It supports sector and topic-specific needs. Standards for cloud, privacy, telecom, energy and health let organizations adapt the ISMS to their context.
5. It enables integration. 27001 follows the ISO harmonized structure (formerly Annex SL), so it combines easily with ISO 9001, ISO 22301, ISO/IEC 20000-1 and others.
What It Is: Structure of the Family
ISO/IEC 27000 groups the family into several categories.
A. Vocabulary standard
ISO/IEC 27000 (latest edition 2018): Overview and vocabulary. It introduces ISMS concepts and the family, and defines terms. It is freely available from ISO.
B. Requirements standards (they use 'shall'; conformity can be assessed)
ISO/IEC 27001:2022: ISMS - Requirements. It contains clauses 4 to 10 and the normative Annex A.
- Clause 4: Context of the organization
- Clause 5: Leadership
- Clause 6: Planning, including risk assessment, risk treatment and information security objectives
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance evaluation
- Clause 10: Improvement
Annex A lists 93 controls in 4 themes:
- Organizational: 37 controls
- People: 8 controls
- Physical: 14 controls
- Technological: 34 controls
Amendment 1:2024 added climate change considerations to clauses 4.1 and 4.2.
ISO/IEC 27006 (now 27006-1:2024): Requirements for bodies providing audit and certification of ISMS. It supplements ISO/IEC 17021-1 and is used to accredit certification bodies, not to certify organizations.
ISO/IEC 27009: Sector-specific application of ISO/IEC 27001 - Requirements. It explains how to write sector-specific standards that add to or refine 27001.
C. General guideline standards (they use 'should'; they are not certifiable)
ISO/IEC 27002:2022: Information security controls. It gives implementation guidance for each Annex A control, including its purpose and control attributes (control type, security properties, cybersecurity concepts, operational capabilities and security domains).
ISO/IEC 27003:2017: ISMS - Guidance. It explains how to implement the requirements in clauses 4 to 10.
ISO/IEC 27004:2016: Monitoring, measurement, analysis and evaluation. It supports clause 9.1.
ISO/IEC 27005:2022: Guidance on managing information security risks. It supports clauses 6.1 and 8.2 to 8.3.
ISO/IEC 27007:2020: Guidelines for ISMS auditing. It supplements ISO 19011.
ISO/IEC TS 27008: Guidelines for the assessment of information security controls. It covers technical reviews of controls.
ISO/IEC 27013: Integrated implementation of 27001 and ISO/IEC 20000-1.
ISO/IEC 27014: Governance of information security.
D. Sector-specific guideline standards
- ISO/IEC 27010: Inter-sector and inter-organizational communications
- ISO/IEC 27011: Telecommunications organizations
- ISO/IEC 27017: Information security controls for cloud services
- ISO/IEC 27018: Protection of PII in public clouds acting as PII processors
- ISO/IEC 27019: Energy utility industry
- ISO 27799: Health informatics
E. Control-specific and topic guidelines (27030 series and others)
- 27031: ICT readiness for business continuity
- 27032: Cybersecurity guidelines
- 27033: Network security
- 27034: Application security
- 27035: Incident management
- 27036: Information security for supplier relationships
- 27037: Identification, collection, acquisition and preservation of digital evidence
F. Privacy
ISO/IEC 27701: Privacy Information Management System (PIMS). The 2019 edition was an extension to 27001 and 27002. The 2025 revision became a standalone management system standard. It is certifiable.
How It Works: The Relationships
Think of the family as a hub and spokes, with ISO/IEC 27001 as the hub.
1. Building the ISMS
An organization defines its context and scope (27001 clause 4), using 27003 for guidance. It then assesses and treats risks (clause 6.1.2 and 6.1.3), using 27005 for the method.
2. Selecting controls
The organization determines the controls it needs and compares them with Annex A to ensure nothing necessary has been omitted. It then produces a Statement of Applicability (SoA) that justifies each inclusion and exclusion. Implementation guidance comes from 27002 and, where relevant, from 27017, 27018 or other sector standards.
3. Measuring and improving
Performance is monitored and measured under clause 9.1, guided by 27004. Internal audit (clause 9.2) and management review (clause 9.3) feed corrective action and continual improvement under clause 10.
4. Auditing and certification
Auditors plan and conduct audits using ISO 19011 together with ISO/IEC 27007. Technical control reviews may use 27008. Certification bodies operate under ISO/IEC 17021-1 and ISO/IEC 27006, and accreditation bodies assess them against these standards.
Key principle: 'shall' means a requirement, 'should' a recommendation, 'may' a permission and 'can' a possibility. Nonconformities can only be raised against requirements: those of 27001, the organization's own documented ISMS requirements, or applicable legal and contractual requirements. They cannot be raised against 27002 guidance on its own.
Exam Tips: Answering Questions on The ISO/IEC 27000 Family of Standards
1. Memorize the 'big seven'.
- 27000: vocabulary
- 27001: requirements
- 27002: controls guidance
- 27003: implementation guidance
- 27004: measurement
- 27005: risk management
- 27006 and 27007: certification bodies and auditing
Many questions simply test these mappings.
2. Certification questions. Only 27001 (and 27701 for privacy) is certifiable for organizations. If an option says an organization is 'certified to ISO/IEC 27002', it is wrong.
3. Do not mix up 27006 and 27007.
- 27006 contains requirements for certification bodies.
- 27007 contains guidelines for auditors and audit programmes.
- 27008 is about assessing controls.
4. Know the 2022 numbers. Annex A has 93 controls in 4 themes (37 organizational, 8 people, 14 physical, 34 technological). Watch for distractors based on the 2013 edition, which had 114 controls in 14 domains.
5. Know that Annex A is normative. The requirement to compare controls with Annex A and produce an SoA is mandatory. However, individual controls may be excluded with justification, based on risk assessment and other requirements.
6. Scenario questions. When a scenario describes an auditee ignoring 27002 implementation advice, ask yourself whether a 27001 requirement is breached. Examples include the SoA, risk treatment, or the organization's own policy. If none is breached, the best answer is usually an opportunity for improvement, not a nonconformity.
7. Match context to sector standards.
- Cloud provider: 27017
- Cloud provider processing PII: 27018
- Privacy management: 27701
- Telecom: 27011
- Energy: 27019
- Healthcare: 27799
- Incidents: 27035
- Suppliers: 27036
- Digital evidence: 27037
8. Use 27000 definitions. Answer terminology questions using the official definitions, not everyday meanings. For example, information security is the preservation of confidentiality, integrity and availability, and risk is the effect of uncertainty on objectives.
9. Remember the harmonized structure. Clauses 4 to 10 are common to ISO management system standards. This explains why integration questions (for example 27013 with ISO/IEC 20000-1) favour combined management systems.
10. Eliminate distractors systematically. Check three things in each option:
- Requirement or guideline?
- Organization, auditor or certification body?
- Generic or sector-specific?
These three filters remove most wrong answers.
11. In open-book exams (such as PECB), justify your answers by citing the clause or standard, for example 'per ISO/IEC 27001 clause 6.1.3 d)'. This shows auditor-level reasoning.
Summary
The ISO/IEC 27000 family is a structured ecosystem:
- One vocabulary standard (27000)
- One certifiable requirements standard for organizations (27001)
- Requirements for certification bodies (27006)
- A large body of supporting guidance: generic, sector-specific and topic-specific
Mastering who uses each standard, for what purpose, and with what level of obligation is essential both for passing the Lead Auditor exam and for conducting credible, evidence-based ISMS audits.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!