oSIST prEN ISO/IEC 27000:2025
(Main)Information security, cybersecurity and privacy protection - Information security management systems - Overview (ISO/DIS 27000:2025)
Information security, cybersecurity and privacy protection - Information security management systems - Overview (ISO/DIS 27000:2025)
This document gives an overview of the concepts and principles of documents related to information security management system (ISMS), including ISO/IEC 27001.
Informationstechnik - Sicherheitsverfahren - Informationssicherheitsmanagementsysteme - Überblick und Terminologie (ISO/IEC DIS 27000:2025)
Sécurité de l'information, cybersécurité et protection de la vie privée - Systèmes de management de la sécurité de l'information - Vue d'ensemble (ISO/DIS 27000:2025)
ISO/IEC 27000:2018 offre une vue d'ensemble des systèmes de management de la sécurité de l'information (SMSI). Il comprend également les termes et définitions d'usage courant dans la famille de normes du SMSI. Le présent document est applicable à tous les types et à toutes les tailles d'organismes (par exemple: les entreprises commerciales, les organismes publics, les organismes à but non lucratif).
Les termes et les définitions fournis dans le présent document:
- couvrent les termes et les définitions d'usage courant dans la famille de normes du SMSI;
- ne couvrent pas l'ensemble des termes et des définitions utilisés dans la famille de normes du SMSI;
- ne limitent pas la famille de normes du SMSI en définissant de nouveaux termes à utiliser.
Informacijska varnost, kibernetska varnost in varovanje zasebnosti - Sistemi vodenja informacijske varnosti - Pregled (ISO/DIS 27000:2025)
General Information
Relations
Standards Content (Sample)
SLOVENSKI STANDARD
01-september-2025
Informacijska varnost, kibernetska varnost in varovanje zasebnosti - Sistemi
vodenja informacijske varnosti - Pregled (ISO/DIS 27000:2025)
Information security, cybersecurity and privacy protection - Information security
management systems - Overview (ISO/DIS 27000:2025)
Informationstechnik - Sicherheitsverfahren -
Informationssicherheitsmanagementsysteme - Überblick und Terminologie (ISO/IEC DIS
27000:2025)
Sécurité de l'information, cybersécurité et protection de la vie privée - Systèmes de
management de la sécurité de l'information - Vue d'ensemble (ISO/DIS 27000:2025)
Ta slovenski standard je istoveten z: prEN ISO/IEC 27000
ICS:
01.040.35 Informacijska tehnologija. Information technology
(Slovarji) (Vocabularies)
03.100.70 Sistemi vodenja Management systems
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
DRAFT
International
Standard
ISO/IEC DIS 27000
ISO/IEC JTC 1/SC 27
Information security, cybersecurity
Secretariat: DIN
and privacy protection —
Voting begins on:
Information security management
2025-07-15
systems — Overview
Voting terminates on:
ICS: 35.030; 01.040.35
2025-10-07
THIS DOCUMENT IS A DRAFT CIRCULATED
FOR COMMENTS AND APPROVAL. IT
IS THEREFORE SUBJECT TO CHANGE
AND MAY NOT BE REFERRED TO AS AN
INTERNATIONAL STANDARD UNTIL
PUBLISHED AS SUCH.
This document is circulated as received from the committee secretariat.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL,
TECHNOLOGICAL, COMMERCIAL AND
USER PURPOSES, DRAFT INTERNATIONAL
STANDARDS MAY ON OCCASION HAVE TO
ISO/CEN PARALLEL PROCESSING
BE CONSIDERED IN THE LIGHT OF THEIR
POTENTIAL TO BECOME STANDARDS TO
WHICH REFERENCE MAY BE MADE IN
NATIONAL REGULATIONS.
RECIPIENTS OF THIS DRAFT ARE INVITED
TO SUBMIT, WITH THEIR COMMENTS,
NOTIFICATION OF ANY RELEVANT PATENT
RIGHTS OF WHICH THEY ARE AWARE AND TO
PROVIDE SUPPORTING DOCUMENTATION.
Reference number
© ISO/IEC 2025
ISO/IEC DIS 27000:2025(en)
DRAFT
ISO/IEC DIS 27000:2025(en)
International
Standard
ISO/IEC DIS 27000
ISO/IEC JTC 1/SC 27
Information security, cybersecurity
Secretariat: DIN
and privacy protection —
Voting begins on:
Information security management
systems — Overview
Voting terminates on:
ICS: 35.030; 01.040.35
THIS DOCUMENT IS A DRAFT CIRCULATED
FOR COMMENTS AND APPROVAL. IT
IS THEREFORE SUBJECT TO CHANGE
AND MAY NOT BE REFERRED TO AS AN
INTERNATIONAL STANDARD UNTIL
PUBLISHED AS SUCH.
This document is circulated as received from the committee secretariat.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL,
© ISO/IEC 2025
TECHNOLOGICAL, COMMERCIAL AND
USER PURPOSES, DRAFT INTERNATIONAL
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
STANDARDS MAY ON OCCASION HAVE TO
ISO/CEN PARALLEL PROCESSING
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
BE CONSIDERED IN THE LIGHT OF THEIR
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
POTENTIAL TO BECOME STANDARDS TO
WHICH REFERENCE MAY BE MADE IN
or ISO’s member body in the country of the requester.
NATIONAL REGULATIONS.
ISO copyright office
RECIPIENTS OF THIS DRAFT ARE INVITED
CP 401 • Ch. de Blandonnet 8
TO SUBMIT, WITH THEIR COMMENTS,
CH-1214 Vernier, Geneva
NOTIFICATION OF ANY RELEVANT PATENT
Phone: +41 22 749 01 11
RIGHTS OF WHICH THEY ARE AWARE AND TO
PROVIDE SUPPORTING DOCUMENTATION.
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2025
ISO/IEC DIS 27000:2025(en)
© ISO/IEC 2025 – All rights reserved
ii
ISO/IEC DIS 27000:2025(en)
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Concepts and principles . 2
4.1 Concepts .2
4.1.1 The need for information security .2
4.1.2 Information .3
4.1.3 Information security . .3
4.1.4 Risks are constantly changing .3
4.1.5 Risk treatment plan .4
4.1.6 Purpose of an information security management system (ISMS) .4
4.1.7 Importance of an ISMS .4
4.1.8 Process approach .5
4.1.9 Scope .5
4.2 Principles .5
4.2.1 Establishing, implementing, maintaining and improving an ISMS .5
4.2.2 Successful ISMS implementation .5
4.2.3 Determining information security requirements .6
4.2.4 Integration into business processes .6
5 Documents related to ISMS including ISO/IEC 27001 . 6
5.1 General .6
5.2 ISO/IEC 27001 (Specification of an ISMS) .6
5.3 Candidate necessary information security controls .6
5.3.1 ISO/IEC 27002 (Information security controls) .6
5.3.2 ISO/IEC 27010 (Inter-sector and inter-organizational communications) .7
5.3.3 ISO/IEC 27011 (Telecommunications organizations) .7
5.3.4 ISO/IEC 27017 (Cloud services).7
5.3.5 ISO/IEC 27019 (Energy utility industry) .7
5.4 Fulfilment of ISMS requirements .7
5.4.1 ISO/IEC 27003 (ISMS guidance) .7
5.4.2 ISO/IEC 27004 (Monitoring, measurement, analysis and evaluation) .7
5.4.3 ISO/IEC 27005 (Guidance on managing information security risks) .7
5.4.4 ISO/IEC 27007 (ISMS auditing) .7
5.5 Use of ISMS .7
5.5.1 ISO/IEC 27013 (Integrated implementation with ISO/IEC 20000-1) .7
5.5.2 ISO/IEC 27014 (Governance of information security) .8
5.5.3 ISO/IEC TR 27016 (Organizational economics) .8
5.5.4 ISO/IEC TR 27029 (ISO/IEC 27002 and ISO and IEC standards) .8
5.6 Control assessment, attributes, processes and competence .8
5.6.1 ISO/IEC TS 27008 (Assessment of information security controls) .8
5.6.2 ISO/IEC 27021 (Competence requirements for ISMS professionals) .8
5.6.3 ISO/IEC TS 27022 (ISMS processes) .8
5.6.4 ISO/IEC 27028 (ISO/IEC 27002 attributes) .8
5.7 Conformity assessment .8
5.7.1 ISO/IEC 27006-1 (Requirements for bodies providing audit and certification) .8
5.8 Relationships between the standards .8
Bibliography .10
© ISO/IEC 2025 – All rights reserved
iii
ISO/IEC DIS 27000:2025(en)
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject of patent
rights. ISO shall not be held responsible for identifying any or all such patent rights. Details of any patent
rights identified during the development of the document will be in the Introduction and/or on the ISO list of
patent declarations received (see www.iso.org/patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This do
...
Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.