ISO/IEC 27000:2009  Information technology — Security techniques — Information security management systems - Overview and vocabulary

The scope of ISO/IEC 27000 is “to specify the fundamental principles, concepts and vocabulary for the ISO/IEC 27000 (information security management system) series of documents.”

ISO/IEC 27000 contains the overview and vocabulary, in other words:

  • An overview of the ISO27k standards showing how they are used collectively to plan, implement, certify and operate an ISMS, with a basic introduction to information security, risk management and management systems
  • Carefully-worded definitions for the information security-related terms as they are used throughout the ISO27k standards. 

Information security, like most technical subjects, is evolving a complex web of terminology.  Several core terms in information security (such as “risk”) have different meanings according to the context and the reader’s preconceptions.  Few authors take the trouble to define precisely what they mean but this is unacceptable in the standards arena as it leads to confusion and devalues formal assessment and certification.

ISO/IEC 27000 is similar to other vocabulary and definitions standards and will hopefully become a generally-accepted reference for information security terms amongst the information security profession.  It largely supersedes the terms and definitions embedded in ISO27k standards already published plus, to a large extent, related guidelines such as ISO/IEC Guide 2:1996 “Standardization and related activities – General vocabulary”, ISO/IEC Guide 73:2002 “Risk management – Vocabulary – Guidelines for use in standards” ISO/IEC 2382-8: “Information technology - Vocabulary Part 8: Security” and ISO 9000, the quality assurance standard.

 

Hot stuff! ISO/IEC 27000 is available as a FREE download.

Revision of the standard

ISO/IEC 27000 will be revised more often than most other standards in order to reflect other ISO27k standards currently being developed, plus the ongoing revision of ISO/IEC 27001, ISO/IEC 27002 and ISO Guide 73.  The idea is basically to remove the definitions of most information security management terms from other ISO27k standards across into ISO/IEC 27000, except for any that are defined and used differently in particular ISO27k standards.

A revised version of ISO/IEC 27000 is currently in the works.  It will be based on the existing/current versions of ISO/IEC 27001 and 27002.  A further revision later will pick up the revised versions of  27001 and 27002, plus ISO 27799.  The editing team is making an effort to collect terms from the teams working on other ISO27k standards in a comprehensive and systematic way, using a separate internal document to collate, compare and align current and proposed definitions.  This is quite a job since the contexts in which certain word or terms are used often differ between the standards.

The terms “management system”, “policy” and “stakeholder” have been defined by JTC1’s Technical Management Board as part of the ongoing alignment of the management systems standards.  This may cause problems for ISO27k but work continues to address this issue. 

A third WD of ISO/IEC 27000 will be released soon to members of SC27.

 

PS  Software and systems engineering terms defined in ISO/IEC and IEEE standards are searchable online.  The definitions of some information security and risk-related terms differ slightly from those defined in ISO/IEC 27000, so bear this in mind when reading various ISO27k and non-ISO27k standards.

Share
Related Documents
  1. How to Test Application Security – Web and Desktop Application Security Testing Techniques (2641)
  2. Information Security (1194)
  3. ISO 17799 : security standard (1107)
  4. Security Testing Techniques (644)
  5. The 2011 (ISC)2 Global Information Security Workforce Study (1403)
  6. [Webinar] Techniques in Attacking and Defending SOA Web Services (719)
  7. CCNA Pre-assessment Test (1634)
  8. 2011-05-02, Embedded Systems Conference 2011 @ USA (1319)
  9. 2011-04-19, Infosecurity Europe @ UK (953)
  10. How to Secure CXF Web Services with SSL/TLS and WS-Security (1318)
  11. 100+ Open Source/Free Security Tools (1784)
  12. Secfence : Security Testing blog (874)
  13. [Paid] INSECT Pro: a penetration security auditing and testing software solution (965)
  14. Password Recovery for Security Testing (1356)
  15. OWASP Top 10 - 2010 (Security Testing) (1622)
  16. Deploying Secure 802.11 Wireless Networks with Microsoft Windows (1664)
  17. [Paid] Retina : Security Testing tool (1640)
  18. [Apid] AVDS : Automated Vulnerability Detection System (1198)
  19. WCF Security Guide (2133)
  20. Application and Cyber Security Blog (568)