Information technology - Security techniques - Information security management systems - Overview and vocabulary (ISO/IEC 27000:2016)

This International Standard provides the overview of information security management systems, and
terms and definitions commonly used in the ISMS family of standards. This International Standard is
applicable to all types and sizes of organization (e.g. commercial enterprises, government agencies, notfor-
profit organizations).

Informationstechnik - Sicherheitsverfahren - Informationssicherheits-Managementsysteme - Überblick und Terminologie (ISO/IEC 27000:2016)

Technologies de l'information - Techniques de sécurité - Systèmes de gestion de sécurité de l'information - Vue d'ensemble et vocabulaire (ISO/IEC 27000:2016)

Informacijska tehnologija - Varnostne tehnike - Sistemi upravljanja informacijske varnosti - Pregled in izrazje (ISO/IEC 27000:2016)

Ta mednarodni standard podaja pregled nad sistemi upravljanja informacijske varnosti ter izraze in definicije, ki se običajno uporabljajo v skupini standardov za sisteme upravljanja informacijske varnosti. Ta mednarodni standard se uporablja za vse vrste in velikosti organizacij (npr. komercialna podjetja, vladne agencije, neprofitne organizacije).

Ta slovenski standard je istoveten z: EN ISO/IEC 27000:2017
01.040.35 Informacijska tehnologija. Information technology
(Slovarji) (Vocabularies)
03.100.70 Sistemi vodenja Management systems
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EN ISO/IEC 27000
February 2017
ICS 01.040.35; 03.100.70; 35.030
English Version
Information technology - Security techniques -
Information security management systems - Overview and
vocabulary (ISO/IEC 27000:2016)
Technologies de l'information - Techniques de sécurité Informationstechnik - Sicherheitsverfahren -
- Systèmes de gestion de sécurité de l'information - Vue Informationssicherheits-Managementsysteme -
d'ensemble et vocabulaire (ISO/IEC 27000:2016) Überblick und Terminologie (ISO/IEC 27000:2016)
Fourth edition
Information technology — Security
techniques — Information security
management systems — Overview
and vocabulary
Technologies de l’information — Techniques de sécurité — Systèmes de
gestion de sécurité de l’information — Vue d’ensemble et vocabulaire
Reference number
ISO/IEC 27000:2016(E)
ISO/IEC 2016
ISO/IEC 27000:2016(E)
ISO/IEC 27000:2016(E)
Contents Page
Foreword .v
0 Introduction . 1
0.1 Overview . 1
0.2 ISMS family of standards . 1
0.3 Purpose of this International Standard . 2
1 Scope . 2
2 Terms and definitions . 2
3 Information security management systems .14
3.1 General .14
3.2 What is an ISMS? .14
3.2.1 Overview and principles .14
3.2.2 Information.15
3.2.3 Information security .15
3.2.4 Management .15
3.2.5 Management system .16
3.3 Process approach .16
3.4 Why an ISMS is important .16
3.5 Establishing, monitoring, maintaining and improving an ISMS .17
3.5.1 Overview .17
3.5.2 Identifying information security requirements .17
3.5.3 Assessing information security risks .18
3.5.4 Treating information security risks . .18
3.5.5 Selecting and implementing controls .18
3.5.6 Monitor, maintain and improve the effectiveness of the ISMS .19
3.5.7 Continual improvement .19
3.6 ISMS critical success factors .20
3.7 Benefits of the ISMS family of standards .20
4 ISMS family of standards .21
4.1 General information .21
4.2 Standards describing an overview and terminology .22
4.2.1 ISO/IEC 27000 (this International Standard) .22
4.3 Standards specifying requirements .22
4.3.1 ISO/IEC 27001 .22
4.3.2 ISO/IEC 27006 .22
4.4 Standards describing general guidelines .22
4.4.1 ISO/IEC 27002 .22
4.4.2 ISO/IEC 27003 .23
4.4.3 ISO/IEC 27004 .23
4.4.4 ISO/IEC 27005 .23
4.4.5 ISO/IEC 27007 .23
4.4.6 ISO/IEC TR 27008 .23
4.4.7 ISO/IEC 27013 .24
4.4.8 ISO/IEC 27014 .24
4.4.9 ISO/IEC TR 27016 .24
4.5 Standards describing sector-specific guidelines .25
4.5.1 ISO/IEC 27010 .25
4.5.2 ISO/IEC 27011 .

