ISO/IEC FDIS 27014
(Main)Information security, cybersecurity and privacy protection — Governance of information security
General Information
- Abstract
This document provides guidance on concepts, objectives and processes for the governance of information security, by which organizations can evaluate, direct, monitor and communicate the information security-related processes within the organization. The intended audience for this document is: — governing body and top management; — those who are responsible for evaluating, directing and monitoring an information security management system (ISMS) based on ISO/IEC 27001; — those responsible for information security management that takes place outside the scope of an ISMS based on ISO/IEC 27001, but within the scope of governance. This document is applicable to all types and sizes of organizations. All references to an ISMS in this document apply to an ISMS based on ISO/IEC 27001. This document focuses on the three types of ISMS organizations given in Annex B. However, this document can also be used by other types of organizations.
- Status
- Not Published
- Drafting Committee
- ISO/IEC JTC 1/SC 27/WG 1 - Information security management systems
- Current Stage
- 5060 - Close of voting Proof returned by Secretariat
- Start Date
- 12-Aug-2026
- Completion Date
- 11-Aug-2026
Buy Documents
ISO/IEC FDIS 27014 - Information security, cybersecurity and privacy protection — Governance of information security
Overview
ISO/IEC FDIS 27014:2026 focuses on the governance of information security within organizations of all types and sizes. Developed by ISO and IEC, this standard provides structured guidance on the concepts, objectives, and processes necessary for effective information security governance. Its primary aim is to help organizations evaluate, direct, monitor, and communicate their information security management activities, ensuring that security objectives align with organizational strategy, and that risks are managed effectively.
The standard is designed for governing bodies, top management, and all individuals responsible for the oversight or operation of Information Security Management Systems (ISMS), especially those built upon ISO/IEC 27001. It also addresses governance responsibilities for information security management outside the typical ISMS scope but within broader organizational governance.
Key Topics
Information Security Governance Framework
Offers a practical framework, detailing processes by which organizational leadership can influence, monitor, and review information security.Integration with ISO/IEC 27001
Describes how ISMS requirements and governance activities overlap, supporting consistent, risk-based decision-making and continuous improvement.Governance Objectives
Highlights six core governance objectives:- Establishing integrated, entity-wide information security.
- Making risk-based security decisions.
- Directing security strategy in acquisitions and changes.
- Ensuring conformance with regulatory and contractual requirements.
- Fostering a security-positive organizational culture.
- Ensuring information security performance keeps pace with organizational needs.
Governance Processes
Outlines four essential processes:- Evaluate: Strategic review of security performance and needs.
- Direct: Setting policies and strategic directions.
- Monitor: Ongoing oversight, performance measurement, and reporting.
- Communicate: Ensuring relevant information flows to stakeholders at all levels.
Organizational Structure Considerations
Addresses different types of ISMS organizations-whether the ISMS encompasses the whole entity, just a part, or spans multiple entities.
Applications
ISO/IEC FDIS 27014 is widely applicable in various organizational contexts, including:
Strategic Leadership in Information Security
Enables boards, executives, and committees to integrate information security governance with overall corporate governance, supporting informed decision-making and alignment with organizational objectives.ISMS Evaluation and Improvement
Assists organizations in evaluating the effectiveness of their ISMS, guiding risk management, compliance efforts, and continual improvement initiatives.Mergers, Acquisitions, and Outsourcing
Supports risk assessment and alignment of security practices during mergers, acquisitions, adoption of new technologies, and when managing third-party or outsourced services.Regulatory Compliance
Provides a framework for conforming to internal policies, industry regulations, and legal requirements, helping demonstrate due diligence and organizational accountability.Cultural Development
Promotes the creation of a security-positive culture through education, training, awareness, and clear assignment of information security responsibilities.
Related Standards
- ISO/IEC 27001 – Information security management systems – Requirements.
- ISO/IEC 27000 – Overview and vocabulary for information security, cybersecurity, and privacy protection.
- ISO/IEC 38500 – Governance of IT for the organization.
- ISO/IEC 37000 – Guidance on governance of organizations.
Organizations implementing ISO/IEC FDIS 27014 benefit from improved alignment between business goals and security strategy, enhanced resilience against emerging threats, and a clear demonstration of effective governance to regulators and stakeholders. Integrating this standard with other ISO/IEC security and governance frameworks strengthens overall security posture and organizational trust.
Relations
- Effective Date
- 28-Mar-2026
Buy Documents
ISO/IEC FDIS 27014 - Information security, cybersecurity and privacy protection — Governance of information security
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

Bureau Veritas
Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

DNV
DNV is an independent assurance and risk management provider.
Sponsored listings
Frequently Asked Questions
ISO/IEC FDIS 27014 is a draft published by the International Organization for Standardization (ISO). Its full title is "Information security, cybersecurity and privacy protection — Governance of information security". This standard covers: This document provides guidance on concepts, objectives and processes for the governance of information security, by which organizations can evaluate, direct, monitor and communicate the information security-related processes within the organization. The intended audience for this document is: — governing body and top management; — those who are responsible for evaluating, directing and monitoring an information security management system (ISMS) based on ISO/IEC 27001; — those responsible for information security management that takes place outside the scope of an ISMS based on ISO/IEC 27001, but within the scope of governance. This document is applicable to all types and sizes of organizations. All references to an ISMS in this document apply to an ISMS based on ISO/IEC 27001. This document focuses on the three types of ISMS organizations given in Annex B. However, this document can also be used by other types of organizations.
This document provides guidance on concepts, objectives and processes for the governance of information security, by which organizations can evaluate, direct, monitor and communicate the information security-related processes within the organization. The intended audience for this document is: — governing body and top management; — those who are responsible for evaluating, directing and monitoring an information security management system (ISMS) based on ISO/IEC 27001; — those responsible for information security management that takes place outside the scope of an ISMS based on ISO/IEC 27001, but within the scope of governance. This document is applicable to all types and sizes of organizations. All references to an ISMS in this document apply to an ISMS based on ISO/IEC 27001. This document focuses on the three types of ISMS organizations given in Annex B. However, this document can also be used by other types of organizations.
ISO/IEC FDIS 27014 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/IEC FDIS 27014 has the following relationships with other standards: It is inter standard links to ISO/IEC 27014:2020. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
ISO/IEC FDIS 27014 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
FINAL DRAFT
International
Standard
ISO/IEC FDIS
ISO/IEC JTC 1/SC 27
Information security, cybersecurity
Secretariat: DIN
and privacy protection —
Voting begins on:
Governance of information security
2026-06-16
Sécurité de l'information, cybersécurité et protection de la vie
Voting terminates on:
privée — Gouvernance de la sécurité de l'information
2026-08-11
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
FINAL DRAFT
International
Standard
ISO/IEC FDIS
ISO/IEC JTC 1/SC 27
Information security, cybersecurity
Secretariat: DIN
and privacy protection —
Voting begins on:
Governance of information security
Sécurité de l'information, cybersécurité et protection de la vie
Voting terminates on:
privée — Gouvernance de la sécurité de l'information
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2026 – All rights reserved
ii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
document should be noted.
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not received
notice of (a) patent(s) which may be required to implement this document. However, implementers are
cautioned that this may not represent the latest information, which may be obtained from the patent database
available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held responsible for
identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by ITU-T as ITU-T X.1054 (04/2021) and drafted in accordance with its editorial
rules, in collaboration with Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee
SC 27, Information security, cybersecurity and privacy protection.
This third edition cancels and replaces the second edition (ISO/IEC 27014:2020), of which it constitutes a
minor revision.
The changes are as follows:
— document references have been updated to refer to the latest published versions where appropriate;
— Annex A and Annex B have been reordered to follow the order in which they are first cited in the text;
— references to ISO/IEC 27000 have been updated to reflect the change of purpose and scope of the source
document (it is no longer the authoritative source for terms and definitions).
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html and www.iec.ch/national-
committees.
© ISO/IEC 2026 – All rights reserved
iii
INTERNATIONAL STANDARD ISO/IEC 27014:2026 (E)
RECOMMENDATION ITU-T X.1054
Information security, cybersecurity and privacy
protection – Governance of information security
Summary
Recommendation ITU-T X.1054 | International Standard ISO/IEC 27014 provides guidance on the governance of
information security.
Information security is a key issue for organizations, amplified by rapid advances in attack methodologies and
technologies, and corresponding increased regulatory pressures.
The failure of an organization's information security controls can have many adverse impacts on an organization and its
interested parties including but not limited to the undermining of trust.
Governance of information security is the use of resources to ensure effective implementation of information security, and
provides assurance that:
• directives concerning information security will be followed; and
• the governing body will receive reliable and relevant reporting about information security related activities.
This assists the governing body to make decisions concerning the strategic objectives for the organization by providing
information about information security that may affect these objectives. It also ensures that information security strategy
aligns with the overall objectives of the entity.
Managers and others working in organizations need to understand:
• the governance requirements that affect their work; and
• how to meet governance requirements that require them to take action.
History
*
Edition Recommendation Approval Study Group Unique ID
1.0 ITU-T X.1054 2012-09-07 17 11.1002/1000/11594
2.0 ITU-T X.1054 2021-04-30 17 11.1002/1000/14248
Keywords
Information security, information security governance, information security management, ISMS.
*
To access the Recommendation, type the URL https://handle.itu.int/ in the address field of your web
browser, followed by the Recommendation's unique ID. For example, https://handle.itu.int/11.1002/1000/11830-en.
Rec. ITU-T X.1054 (04/2021)
© ISO/IEC 2026 – All rights reserved
iv
FOREWORD
The International Telecommunication Union (ITU) is the United Nations specialized agency in the field of telecom-
munications, information and communication technologies (ICTs). The ITU Telecommunication Standardization
Sector (ITU-T) is a permanent organ of ITU. ITU-T is responsible for studying technical, operating and tariff
questions and issuing Recommendations on them with a view to standardizing telecommunications on a worldwide
basis.
The World Telecommunication Standardization Assembly (WTSA), which meets every four years, establishes the
topics for study by the ITU-T study groups which, in turn, produce Recommendations on these topics.
The approval of ITU-T Recommendations is covered by the procedure laid down in WTSA Resolution 1.
In some areas of information technology which fall within ITU-T's purview, the necessary standards are prepared on
a collaborative basis with ISO and IEC.
NOTE
In this Recommendation, the expression "Administration" is used for conciseness to indicate both a
telecommunication administration and a recognized operating agency.
Compliance with this Recommendation is voluntary. However, the Recommendation may contain certain mandatory
provisions (to ensure, e.g., interoperability or applicability) and compliance with the Recommendation is achieved
when all of these mandatory provisions are met. The words "shall" or some other obligatory language such as "must"
and the negative equivalents are used to express requirements. The use of such words does not suggest that
compliance with the Recommendation is required of any party.
INTELLECTUAL PROPERTY RIGHTS
ITU draws attention to the possibility that the practice or implementation of this Recommendation may involve the
use of a claimed Intellectual Property Right. ITU takes no position concerning the evidence, validity or applicability
of claimed Intellectual Property Rights, whether asserted by ITU members or others outside of the Recommendation
development process.
As of the date of approval of this Recommendation, ITU had not received notice of intellectual property, protected
by patents/software copyrights, which may be required to implement this Recommendation. However, implementers
are cautioned that this may not represent the latest information and are therefore strongly urged to consult the
appropriate ITU-T databases available via the ITU-T website at https://www.itu.int/ITU-T/ipr/.
ITU 2022
All rights reserved. No part of this publication may be reproduced, by any means whatsoever, without the prior
written permission of ITU.
Rec. ITU-T X.1054 (04/2021)
© ISO/IEC 2026 – All rights reserved
v
CONTENTS
Page
1 Scope . 1
2 Normative references . 1
3 Definitions. 1
4 Abbreviations . 2
5 Use and structure of this Recommendation | International Standard . 2
6 Governance and management standards . 2
6.1 Overview . 2
6.2 Governance activities within the scope of an ISMS . 3
6.3 Other related standards . 3
6.4 Thread of governance within the organization. 4
7 Entity governance and information security governance . 4
7.1 Overview . 4
7.2 Objectives . 4
7.2.1 Objective 1: Establish integrated comprehensive entity-wide information security . 4
7.2.2 Objective 2: Make decisions using a risk-based approach . 4
7.2.3 Objective 3: Set the direction of acquisition . 4
7.2.4 Objective 4: Ensure conformance with internal and external requirements . 5
7.2.5 Objective 5: Foster a security-positive culture . 5
7.2.6 Objective 6: Ensure the security performance meets current and future requirements of the entity. 5
7.3 Processes . 5
7.3.1 General . 5
7.3.2 Evaluate . 6
7.3.3 Direct . 6
7.3.4 Monitor . 7
7.3.5 Communicate . 7
8 The governing body's requirements on the ISMS . 8
8.1 Organization and ISMS . 8
8.2 Scenarios (see Annex A) . 8
8.2.1 Type A: The ISMS organization is the whole entity . 8
8.2.2 Type B: The ISMS organization forms a part of a larger entity . 9
8.2.3 Type C: The ISMS organization includes parts of several entities . 9
Annex A Types of ISMS organization . 10
Annex B Governance relationship. 11
Annex C Examples of communication . 12
Bibliography . 13
Rec. ITU-T X.1054 (04/2021)
© ISO/IEC 2026 – All rights reserved
vi
Introduction
The International Telecommunication Union (ITU) is the United Nations specialized agency in the field of telecommunications.
The ITU Telecommunication Standardization Sector (ITU-T) is a permanent organ of ITU. ITU-T is responsible for studying
technical, operating, and tariff questions and issuing Recommendations on them with a view to standardizing telecommunications
on a world-wide basis. The World Telecommunication Standardization Assembly (WTSA), which meets every four years,
establishes the topics for study by the ITU-T study groups that, in turn, produce Recommendations on these topics. The approval
of ITU-T Recommendations is covered by the procedure laid down in WTSA Resolution 1. In some areas of information
technology that fall within ITU-T's purview, the necessary standards are prepared on a collaborative basis with ISO and IEC.
ISO (the International Organization for Standardization) and IEC (the International Electro technical Commission) form the
specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development
of Recommendation | International Standards through technical committees established by the respective organization to deal
with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other
international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In the
field of Information security, cybersecurity and privacy protection, ISO and IEC have established a joint technical committee,
ISO/IEC JTC 1.
This Recommendation | International Standard has been drafted in accordance with the rules given in the ISO/IEC Directives,
Part 2.
The main task of the joint technical committee is to prepare this Recommendation | International Standard. Draft
Recommendation | International Standards adopted by the joint technical committee are circulated to national bodies for voting.
Publication as an International Standard requires approval by at least 75% of the national bodies casting a vote.
Attention is drawn to the possibility that some of the elements of this Recommendation | International Standard may be the
subject of patent rights. ITU, ISO or IEC shall not be held responsible for identifying any or all such patent rights.
Rec. ITU-T X.1054 | ISO/IEC 27014 was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information security, cybersecurity and privacy protection, in collaboration with ITU-T SG17.
Rec. ITU-T X.1054 (04/2021)
© ISO/IEC 2026 – All rights reserved
vii
INTERNATIONAL STANDARD
ITU-T RECOMMENDATION
Information Security, Cybersecurity and Privacy
Protection – Governance of Information Security
1 Scope
This Recommendation | International Standard provides guidance on concepts, objectives and processes for the governance of
information security, by which organizations can evaluate, direct, monitor and communicate the information security-related
processes within the organization.
The intended audience for this document is:
• governing body and top management;
• those who are responsible for evaluating, directing and monitoring an information security management system
(ISMS) based on ISO/IEC 27001;
• those responsible for information security management that takes place outside the scope of an ISMS based on
ISO/IEC 27001, but within the scope of governance.
This Recommendation | International Standard is applicable to all types and sizes of organizations.
All references to an ISMS in this document apply to an ISMS based on ISO/IEC 27001.
This Recommendation | International Standard focuses on the three types of ISMS organizations given in Annex A. However, it
can also be used by other types of organizations.
2 Normative references
The following Recommendations and International Standards contain provisions which, through reference in this text, constitute
provisions of this Recommendation | International Standard. At the time of publication, the editions indicated were valid. All
Recommendations and Standards are subject to revision, and parties to agreements based on this Recommendation | International
Standard are encouraged to investigate the possibility of applying the most recent edition of the Recommendations and Standards
listed below. Members of IEC and ISO maintain registers of currently valid International Standards. The Telecommunication
Standardization Bureau of the ITU maintains a list of currently valid ITU-T Recommendations.
– ISO/IEC 27000:in force, Information security, cybersecurity and privacy protection — Information security
management systems — Overview.
– ISO/IEC 27001:in force, Information security, cybersecurity and privacy protection — Information security
management systems – Requirements.
– ISO/IEC 37000:in force, Governance of organizations – Guidance.
3 Definitions
For the purposes of this Recommendation | International Standard, the following terms and definitions apply.
ISO, IEC and ITU maintain terminology databases for use in standardization at the following addresses:
• IEC Electropedia: available at https://www.electropedia.org/
• ISO Online browsing platform: available at https://www.iso.org/obp
• ITU Terms and Definitions: available at https://www.itu.int/go/terminology-database
3.1 entity: Organization (3.2) and other bodies or parties.
NOTE – An entity can be a group of companies, or a single company, or a non for profit company, or other. The entity has governance
authority over the organization. The entity can be identical to the organization, for example in smaller companies.
3.2 organization: That part of an entity (3.1) which runs and manages an ISMS.
3.3 governing body: Person or group of people who are accountable for the performance and conformance of the entity.
Rec. ITU-T X.1054 (04/2021)
© ISO/IEC 2026 – All rights reserved
3.3 management system: set of interrelated or interacting elements of an organization to establish policies and objectives
and processes to achieve those objectives
Note 1 to entry: A management system can address a single discipline or several disciplines.
Note 2 to entry: The system elements include the organization’s structure, roles and responsibilities, planning and operation.
3.4 top management: Person or group of people who directs and controls an organization (3.2) at the highest level.
NOTE 1 – Top management has the power to delegate authority and provide resources within the organization. If the scope of the
management system covers only part of an entity, then top management refers to those who direct and control that part of the entity. In this
situation, top management are accountable to the governing body of the entity. (Source ISO/IEC 9001)
NOTE 2 – Top management reports to the governing body. Depending on the size and resources of the organization, top management can
be the same as the governing body.
NOTE 3 – ISO/IEC 37001 also provides definitions for governing body and top management.
4 Abbreviations
For the purposes of this Recommendation | International Standard, the following abbreviations apply:
ISMS Information Security Management System
IT Information Technology
5 Use and structure of this Recommendation | International Standard
This Recommendation | International Standard describes how information security governance operates within an ISMS based
upon ISO/IEC 27001, and how these activities can relate to other governance activities which operate outside the scope of an
ISMS. It outlines four main processes of "evaluate", "direct", "monitor" and "communicate" in which an ISMS can be structured
inside an organization, and suggests approaches for integrating information security governance into organizational governance
activities in each of these processes. Finally, Annex B describes the relationships between organizational governance, governance
of information technology and governance of information security.
The ISMS covers the whole of the organization, by definition (see ISO/IEC 27000). It can cover the whole of the entity, or part
of the entity. This is illustrated in Figure A.1.
6 Governance and management standards
6.1 Overview
Governance of information security is the means by which an organization's governing body provides overall direction and
control of activities that affect the security of an organization's information. This direction and control focuses on circumstances
where inadequate information security can adversely affect the organization's ability to achieve its overall objectives. It is
common for a governing body to realise its governance objectives by:
• providing direction by setting strategies and policies;
• monitoring the performance of the organization; and
• evaluating proposals and plans developed by managers.
Management of information security is associated with ensuring the achievement of the objectives of the organization described
within the strategies and policies established by the governing body. This can include interacting with the governing body by:
• providing proposals and plans for consideration by the governing body; and
• providing information to the governing body concerning the performance of the organization.
Effective governance of information security requires both members of the governing body and managers to fulfil their respective
roles in a consistent way.
Rec. ITU-T X.1054 (04/2021)
© ISO/IEC 2026 – All rights reserved
6.2 Governance activities within the scope of an ISMS
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an information
security management system within the context of an organization. It also includes requirements for the assessment and treatment
of information security risks tailored to the needs of the organization.
ISO/IEC 27001 does not use the term "governance" but specifies a number of requirements which are governance activities. The
following list provides examples of these activities. References to the organization and top management are, as previously noted,
associated with the scope of an ISMS based on ISO/IEC 27001.
• ISO/IEC 27001:2022, 4.1 requires the organization to identify what it is aiming to achieve – its information
security goals and objectives. These should be related to, and support, the overall goals and objectives of the
entity. This relates to governance objectives 1, 3 and 4 stated in 7.2 of this Recommendation | International
Standard.
• ISO/IEC 27001:2022, 4.2 requires the organization to identify the interested parties that are relevant to its ISMS,
and the requirements of those interested parties relevant to information security. This relates to governance
objective 4 stated in 7.2 of this Recommendation | International Standard.
• ISO/IEC 27001:2022, 4.3 requires the organization to define the boundaries and applicability of the ISMS to
establish its scope by considering the external issues and internal issues, the requirements, and interfaces and
dependencies. It is also specified that the organization shall build the requirements and expectations of interested
...



