General Information

Abstract

This document gives an overview of the concepts and principles used in the documents related to information security management systems (ISMS), including ISO/IEC 27001. This document is considered to be a horizontal document as it provides an explanation of the concepts and principles that underpin information security and ISMS

Status
Published
Publication Date
14-Jul-2026
Current Stage
6060 - Definitive text made available (DAV) - Publishing
Start Date
15-Jul-2026
Completion Date
15-Jul-2026

Buy Documents

Standard

EN ISO/IEC 27000:2026

English language (20 pages)
Preview
Preview
e-Library read for
×1 day

Overview

EN ISO/IEC 27000:2026 provides a comprehensive overview of the concepts and principles that underlie information security management systems (ISMS). This standard is published by CEN and is based on the ISO/IEC 27000 series, focusing on core definitions and frameworks related to information security, cybersecurity, and privacy protection. As a cornerstone document in the ISMS ecosystem, EN ISO/IEC 27000:2026 helps organizations understand the foundational elements necessary for establishing, implementing, maintaining, and improving an ISMS, including the relationships among related standards such as ISO/IEC 27001.

EN ISO/IEC 27000 serves as a horizontal document, making it crucial for organizations seeking to build or enhance their information security management practices. It offers clarity on key terminology and concepts, ensuring a consistent understanding essential for effective implementation and certification across varied sectors.

Key Topics

  • Information Security Fundamentals
    Defines information security as the preservation of confidentiality, integrity, and availability of information. The standard emphasizes the management of risks associated with information assets in all forms and explains the importance of protecting information entrusted by customers.

  • ISMS Concepts and Principles
    Explains the systematic approach to information security management, including:

    • Identifying information assets
    • Understanding the value and vulnerabilities of these assets
    • Managing risks through risk assessment and risk treatment processes
    • Integrating ISMS into business processes for continual improvement
  • Types of Controls
    The standard highlights essential categories of controls-organizational, people-centric, physical, and technological. Controls are further grouped as preventive, detective, and corrective, each vital for a resilient risk treatment plan.

  • ISMS Implementation and Governance
    Outlines the process approach and principle of continual improvement. Stresses the need for ISMS integration with business operations, alignment with legal and regulatory requirements, and accountability to stakeholders.

  • Horizontal Structure
    This document provides definitions and understanding for all ISMS-related standards, rather than being a terminology list. It clarifies the interconnections between documents such as ISO/IEC 27001 (requirements), ISO/IEC 27002 (controls), and others in the 27000 series.

Applications

The practical value of EN ISO/IEC 27000:2026 extends across organizations of all types and sizes, including public and private sectors, service providers, IT companies, and organizations handling sensitive data.

  • Foundation for ISMS Implementation
    Serves as an entry point for organizations planning to implement an ISMS or pursue ISO/IEC 27001 certification, providing a unified explanation of information security concepts and best practices.

  • Risk Management and Governance
    Supports the establishment of robust risk management frameworks and empowers organizations to develop governance models aligned with international best practices.

  • Policy and Stakeholder Communication
    Enables clear communication of information security requirements to stakeholders, including employees, customers, and regulatory bodies, by establishing common terminology and principles.

  • Integration and Audit Preparation
    Assists organizations in integrating ISMS with other management systems and prepares them for conformity assessments and audits through a standardized approach.

Related Standards

EN ISO/IEC 27000:2026 is closely linked with numerous standards in the ISO/IEC 27000 family:

  • ISO/IEC 27001 – Specifies ISMS requirements.
  • ISO/IEC 27002 – Provides guidelines for information security controls.
  • ISO/IEC 27003 – Offers implementation guidance for ISMS.
  • ISO/IEC 27004 – Covers monitoring and evaluation of ISMS.
  • ISO/IEC 27005 – Addresses management of information security risks.
  • ISO/IEC 27007 – Guidance on ISMS audit programmes.
  • ISO/IEC 27010, 27011, 27017, 27019 – Sector- and technology-specific controls (e.g., telecom, cloud services).
  • ISO/IEC 27013, 27014 – Guidance on integration with other systems and information security governance.
  • ISO/IEC 27006-1 – Requirements for bodies providing ISMS audit and certification.

EN ISO/IEC 27000:2026 provides the essential framework for understanding and applying the family of information security, cybersecurity, and privacy protection standards, supporting organizations in building resilient and compliant ISMS solutions.

Relations

Effective Date
22-May-2024
Effective Date
12-Feb-2026

Buy Documents

Standard

EN ISO/IEC 27000:2026

English language (20 pages)
Preview
Preview
e-Library read for
×1 day

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

EN ISO/IEC 27000:2026 is a standard published by the European Committee for Standardization (CEN). Its full title is "Information security, cybersecurity and privacy protection - Information security management systems - Overview (ISO/IEC 27000:2026)". This standard covers: This document gives an overview of the concepts and principles used in the documents related to information security management systems (ISMS), including ISO/IEC 27001. This document is considered to be a horizontal document as it provides an explanation of the concepts and principles that underpin information security and ISMS

This document gives an overview of the concepts and principles used in the documents related to information security management systems (ISMS), including ISO/IEC 27001. This document is considered to be a horizontal document as it provides an explanation of the concepts and principles that underpin information security and ISMS

EN ISO/IEC 27000:2026 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.

EN ISO/IEC 27000:2026 has the following relationships with other standards: It is inter standard links to EN ISO/IEC 27000:2020, ISO/IEC 27000:2026. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

EN ISO/IEC 27000:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


SLOVENSKI STANDARD
01-november-2026
Nadomešča:
SIST EN ISO/IEC 27000:2020
Informacijska varnost, kibernetska varnost in varstvo zasebnosti - Sistemi vodenja
informacijske varnosti - Pregled (ISO/IEC 27000:2026)
Information security, cybersecurity and privacy protection - Information security
management systems - Overview (ISO/IEC 27000:2026)
Informationstechnik - Sicherheitsverfahren -
Informationssicherheitsmanagementsysteme - Überblick und Terminologie (ISO/IEC
27000:2026)
Sécurité de l'information, cybersécurité et protection de la vie privée - Systèmes de
management de la sécurité de l'information - Vue d'ensemble (ISO/IEC 27000:2026)
Ta slovenski standard je istoveten z: EN ISO/IEC 27000:2026
ICS:
01.040.35 Informacijska tehnologija. Information technology
(Slovarji) (Vocabularies)
03.100.70 Sistemi vodenja Management systems
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EUROPEAN STANDARD EN ISO/IEC 27000

NORME EUROPÉENNE
EUROPÄISCHE NORM
July 2026
ICS 35.030
Supersedes EN ISO/IEC 27000:2020
English version
Information security, cybersecurity and privacy protection
- Information security management systems - Overview
(ISO/IEC 27000:2026)
Sécurité de l'information, cybersécurité et protection Informationstechnik - Sicherheitsverfahren -
de la vie privée - Systèmes de management de la Informationssicherheitsmanagementsysteme -
sécurité de l'information - Vue d'ensemble (ISO/IEC Überblick und Terminologie (ISO/IEC 27000:2026)
27000:2026)
This European Standard was approved by CEN on 2 July 2026.

CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.

CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2026 CEN/CENELEC All rights of exploitation in any form and by any means
Ref. No. EN ISO/IEC 27000:2026 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3

European foreword
This document (EN ISO/IEC 27000:2026) has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology" in collaboration with Technical Committee CEN-CENELEC/ JTC 13
“Cybersecurity and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by January 2028, and conflicting national standards shall
be withdrawn at the latest by January 2028.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
This document supersedes EN ISO/IEC 27000:2020.
Any feedback and questions on this document should be directed to the users’ national standards
body/national committee. A complete listing of these bodies can be found on the CEN and CENELEC
websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 27000 has been approved by CEN-CENELEC as EN ISO/IEC 27000:2026 without any
modification.
International
Standard
ISO/IEC 27000
Sixth edition
Information security, cybersecurity
2026-07
and privacy protection —
Information security management
systems — Overview
Sécurité de l'information, cybersécurité et protection de
la vie privée — Systèmes de management de la sécurité de
l'information — Vue d'ensemble
Horizontal document
Reference number
ISO/IEC 27000:2026(en) © ISO/IEC 2026

ISO/IEC 27000:2026(en)
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC 27000:2026(en)
Contents Page
Foreword .iv
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Concepts and principles . 2
4.1 Concepts .2
4.1.1 The need for information security .2
4.1.2 Information .3
4.1.3 Information security . .3
4.1.4 Constantly changing risks .3
4.1.5 Risk treatment plan .3
4.1.6 Purpose of an information security management system (ISMS) .4
4.1.7 Importance of an ISMS .4
4.1.8 Process approach .5
4.1.9 Scope .5
4.2 Principles .5
4.2.1 Establishing, implementing, maintaining and improving an ISMS .5
4.2.2 Successfully implementing an ISMS .5
4.2.3 Determining information security requirements .5
4.2.4 Integration into business processes .6
5 Documents related to ISMS including ISO/IEC 27001 . 6
5.1 General .6
5.2 ISO/IEC 27001 (specification of an ISMS) .6
5.3 Candidate necessary information security controls .7
5.3.1 ISO/IEC 27002 (information security controls) .7
5.3.2 ISO/IEC 27010 (inter-sector and inter-organizational communications) .7
5.3.3 ISO/IEC 27011 (telecommunications organizations) .7
5.3.4 ISO/IEC 27017 (cloud services) .7
5.3.5 ISO/IEC 27019 (energy utility industry) .7
5.4 Fulfilment of ISMS requirements .7
5.4.1 ISO/IEC 27003 (ISMS guidance) .7
5.4.2 ISO/IEC 27004 (monitoring, measurement, analysis and evaluation) .7
5.4.3 ISO/IEC 27005 (guidance on managing information security risks) .7
5.4.4 ISO/IEC 27007 (ISMS auditing) .7
5.5 Use of ISMS .8
5.5.1 ISO/IEC 27013 (integrated implementation of ISO/IEC 27001 and ISO/IEC
20000-1) .8
5.5.2 ISO/IEC 27014 (governance of information security) .8
5.5.3 ISO/IEC TR 27016 (organizational economics) .8
5.6 Control assessment, attributes, processes and competence .8
5.6.1 ISO/IEC TS 27008 (assessment of information security controls) .8
5.6.2 ISO/IEC 27021 (competence requirements for ISMS professionals) .8
5.6.3 ISO/IEC TS 27022 (ISMS processes) .8
5.6.4 ISO/IEC 27028 (ISO/IEC 27002 attributes) .8
5.7 ISO/IEC 27006-1 (Conformity assessment) .8
5.8 Relationships between the standards .8
Bibliography .10

© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC 27000:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cybersecurity and privacy protection, in collaboration with the
European Committee for Standardization (CEN) Technical Committee CEN/CLC/JTC 13, Cybersecurity and
data protection, in accordance with the Agreement on technical cooperation between ISO and CEN (Vienna
Agreement).
This sixth edition cancels and replaces the fifth edition (ISO/IEC 27000:2018), which has been technically
revised.
The main changes are as follows:
— the title has been modified;
— the structure of the document has been changed to stress its primary role, which is to provide an
overview of, and explain the relationships between, documents related to ISMS (information security
management systems) including ISO/IEC 27001;
— text presenting the concepts and principles of information security and information security management
systems has been added;
— Clause 3 has been modified to only contain definitions for those terms used in presenting the concepts
and principles described in this document;
— it is no longer a terminology document.
This document has been given the status of a horizontal document in accordance with the ISO/IEC Directives,
Part 1.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
iv
ISO/IEC 27000:2026(en)
© ISO/IEC 2026 – All rights reserved
v
ISO/IEC 27000:2026(en)
Introduction
This document explains the concepts and principles that underpin information security and information
security management systems. It provides an overview of all documents related to ISMS (information
security management systems) including ISO/IEC 27001 and explains the relationship between them.

© ISO/IEC 2026 – All rights reserved
vi
International Standard ISO/IEC 27000:2026(en)
Information security, cybersecurity and privacy protection —
Information security management systems — Overview
1 Scope
This document gives an overview of the concepts and principles used in the documents related to information
security management systems (ISMS), including ISO/IEC 27001.
This document is considered to be a horizontal document as it provides an explanation of the concepts and
principles that underpin information security and ISMS.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
information security
preservation of confidentiality (3.2), integrity (3.3) and availability (3.4) of information
3.2
confidentiality
property that information is not made available or disclosed to unauthorized individuals, entities, or
processes
3.3
integrity
property of accuracy and completeness
3.4
availability
property of being accessible and usable on demand by an authorized entity
3.5
event
occurrence or change of a particular set of circumstances
[SOURCE: ISO/IEC 27005:2022, 3.1.11, modified — The two notes to entry have been omitted.]
3.6
likelihood
chance of something happening
[SOURCE: ISO/IEC 27005:2022, 3.1.13, modified — The two notes to entry have been omitted.]

© ISO/IEC 2026 – All rights reserved
ISO/IEC 27000:2026(en)
3.7
consequence
outcome of an event (3.5) affecting objectives
[SOURCE: ISO/IEC 27005:2022, 3.1.14, modified — The three notes to entry have been omitted.]
3.8
risk
effect of uncertainty on objectives
[SOURCE: ISO/IEC 27005:2022, 3.1.3, modified — The seven notes to entry have been omitted.]
3.9
risk treatment
process to modify risk (3.8)
3.10
control
measure that maintains and/or modifies risk (3.8)
[SOURCE: ISO/IEC 27002:2022, 3.1.8, modified — The two notes to entry have been omitted.]
3.11
specified requirement
need or expectation that is stated
[SOURCE: ISO/IEC 17000:2020, 4.1, modified — The four notes to entry have been omitted.]
3.12
conformity assessment
demonstration that specified requirements (3.12) relating to a product, process, system, person or body are
fulfilled
[SOURCE: ISO/IEC 17000:2020, 5.1, modified — The two notes to entry have been omitted.]
4 Concepts and principles
4.1 Concepts
4.1.1 The need for information security
Organizations of all types and sizes:
a) collect, process, store, transmit and delete information;
b) recognize that some information (and the associated information and commun
...