The ISO/IEC 27000 Family & the Structure of ISO/IEC 27001

Understand how ISO/IEC 27001 fits into a wider family of related standards, and how the standard itself is organized — mandatory management clauses versus the Annex A control reference.

Easy 40m 2 tasks

Learning Objectives

  • Identify the role of at least 4 standards in the ISO/IEC 27000 family
  • Distinguish the mandatory clauses (4-10) from the Annex A control reference
  • Explain why certification audits check clauses 4-10 for every organization, but Annex A only where selected
  • Describe how ISO/IEC 27002 relates to Annex A of ISO/IEC 27001

ISO/IEC 27001 is not a standalone document — it is the central certifiable standard in a family of related publications, each covering a different aspect of information security management. Understanding the family helps you know which document to reach for when you need implementation detail that 27001 itself doesn't provide.

Key members of the 27000 family

Standard What it covers Is it certifiable?
ISO/IEC 27000 Overview and vocabulary — the common definitions used across the whole family No — reference document
ISO/IEC 27001 The ISMS requirements themselves — what an organization must do to be certified Yes — this is the certifiable standard
ISO/IEC 27002 Detailed implementation guidance for the Annex A controls — the "how" behind 27001's "what" No — a companion guide
ISO/IEC 27005 Detailed guidance specifically on information security risk management No — a companion guide
ISO/IEC 27701 Extends an ISMS to cover privacy information management (PIMS) — relevant for GDPR-adjacent obligations Yes, as an extension to a certified ISMS
ISO/IEC 27017 / 27018 Cloud-specific security and privacy guidance No — companion guides

A common point of confusion: you get certified against ISO/IEC 27001, not against ISO/IEC 27002. 27002 exists purely to help you implement the controls that 27001's Annex A references — an auditor checks whether you meet 27001's requirements, using 27002 only as an interpretive aid if needed.

Two very different halves of ISO/IEC 27001

The standard itself has two parts that behave completely differently in an audit, and mixing them up is one of the most common Foundation-level mistakes:

ISO/IEC 27001:2022
│
├── Clauses 410 (the "main body")
│     Management system REQUIREMENTS.
│     Written with "shall"meaning mandatory.
│     EVERY certified organization must satisfy ALL of these,
│     with no exceptions or selection involved.
│
└── Annex A (93 controls, 4 themes)
      A REFERENCE LIST of possible controls.
      Not all 93 are mandatory for every organizationyou SELECT which apply based on your own risk
      assessment, and justify your selection (or exclusion)
      in the Statement of Applicability (SoA).

Clauses 4-10 describe the management system itself: how you determine context (4), how leadership commits to it (5), how you plan and assess risk (6), what support and resources you provide (7), how you operate day to day (8), how you evaluate performance (9), and how you improve (10). These are covered in depth in the next two lessons.

Annex A, by contrast, is a menu, not a checklist you complete in full. A five-person software startup and a 5,000-employee bank might both be legitimately certified while implementing very different subsets of the 93 controls — because their risk assessments (clause 6) identified different needs. What both organizations cannot skip is the process of properly assessing risk and justifying their Annex A decisions in the first place — that requirement lives in the mandatory clauses.

Why this distinction matters in an audit

An auditor will check clauses 4-10 against every certified organization identically — there's no "we don't need a management review" exemption. But for Annex A, the auditor's question is never "did you implement control 8.7?" in isolation — it's "does your Statement of Applicability correctly justify why you did or didn't implement control 8.7, and does your risk assessment support that decision?" A control marked "not applicable" with a solid justification is not a finding. A control marked "implemented" with no evidence behind it is a serious finding — regardless of whether the control itself would have been a good idea.

Without looking back at the lesson content, try to recall: which standard would you open if you needed detailed guidance on how to actually implement an access control policy that satisfies Annex A control 5.15? Which one would you open for detailed risk assessment methodology guidance?

✦ Answer the questions to complete this task

Which standard provides detailed implementation guidance for Annex A controls?

Which standard is dedicated specifically to risk management methodology detail?

For each of these statements, decide whether it describes something from the mandatory clauses (4-10) or from Annex A: (a) 'the organization shall conduct internal audits at planned intervals', (b) 'access rights shall be provisioned, reviewed, modified and removed in accordance with the organization's access control policy', (c) 'top management shall demonstrate leadership and commitment'.

✦ Answer the questions to complete this task

Statement (b), about provisioning and reviewing access rights, comes from which part of the standard?

Statement (a), about conducting internal audits at planned intervals, comes from which part of the standard?

💪 Exercises & Challenges

📝 MCQ Easy +20 XP

ISO 27000 Family — MCQ

ISO 27000 Family — MCQ

Start →
⚙️ Practical Medium +30 XP

Build a Family Reference Card

Build a Family Reference Card

Start →
🚩 Challenge Medium +40 XP

Certifiable or Not?

Certifiable or Not?

Start →