← Back to Knowledge Base

Understanding the Differences Between ISO/IEC 27000, 27001, 27002 and 27005 in the ISMS Family

ISO 27001 Compliance

The ISO/IEC 27000 (ISO27k) family is the globally recognised framework for information security management. Many practitioners confuse ISO/IEC 27000, 27001, 27002 and 27005 because they work closely together in an Information Security Management System (ISMS). This article clarifies the distinct purpose, scope and relationship of these four core standards. ISO/IEC 27000 delivers foundational vocabulary and overview; ISO/IEC 27001 sets the auditable requirements for an ISMS and is the only certifiable standard among them; ISO/IEC 27002 provides a library of information security controls and implementation guidance; ISO/IEC 27005 defines the methodology for information security risk assessment and risk treatment. The article also explains the workflow connecting these standards, answering a common question: why organisations still need ISO/IEC 27005 even though ISO/IEC 27002 contains extensive security control guidance.

Introduction

The ISO/IEC 27000 series, commonly known as ISO27k, establishes a systematic approach to protect information assets, intellectual property, customer data and employee records. While ISO/IEC 27000, 27001, 27002 and 27005 are frequently referenced together in ISMS projects, each has a unique role. They are not competing documents; they complement one another to build a complete information security management system.

ISO/IEC 27000: Overview and Vocabulary

ISO/IEC 27000 serves as the dictionary and introductory guide for the entire ISO27k family. It defines standard terminology, core concepts and principles of ISMS, and summarises what each standard in the family does. It contains no mandatory requirements, no security controls and no risk assessment procedures. Its main function is to align all stakeholders on consistent definitions when reading other ISO27k documents. Any team starting an ISMS project can use ISO/IEC 27000 to avoid misunderstandings of ISMS-related terms.

ISO/IEC 27001: ISMS Requirements (Certifiable Standard)

ISO/IEC 27001 is the only standard in this group that can be formally audited and certified. It sets out mandatory requirements for establishing, implementing, maintaining and continually improving an Information Security Management System. It defines the management system structure: scope definition, leadership commitment, planning, support, operation, performance evaluation and improvement.

ISO/IEC 27001 mandates that organisations conduct information security risk assessment and risk treatment. It also requires a Statement of Applicability (SoA), where organisations select or exclude security controls based on risk results. Importantly, ISO/IEC 27001 does not give detailed security control descriptions or a detailed risk assessment algorithm. It only states what must be achieved, not how to implement it.

ISO/IEC 27002: Information Security Controls

ISO/IEC 27002 is the collection of information security controls and implementation guidance. It lists a comprehensive set of best-practice controls covering access control, cryptography, physical security, change management, incident management, supplier security and many other domains. Organisations select suitable controls from ISO/IEC 27002 during risk treatment to mitigate identified risks, and document their selection within the ISO/IEC 27001 SoA.

A critical point: ISO/IEC 27002 only provides available security measures. It cannot tell an organisation which controls are necessary for its specific business context. Having a long list of controls does not equal risk-based decision making. This limitation creates the need for ISO/IEC 27005.

ISO/IEC 27005: Guidance on Managing Information Security Risks

ISO/IEC 27005 provides the structured methodology for information security risk management. It describes the full risk lifecycle: asset identification, threat and vulnerability identification, risk analysis, risk evaluation and risk treatment options (risk avoidance, risk transfer, risk mitigation, risk acceptance).

ISO/IEC 27001 requires risk assessment but leaves the method open. ISO/IEC 27005 offers the recommended process to perform that risk work. After analysing risks using ISO/IEC 27005, organisations determine which risks need treatment and then pick matching controls from ISO/IEC 27002. This answers the frequent confusion: ISO/IEC 27002 tells you what security actions you can take; ISO/IEC 27005 tells you which actions you should take based on your risk profile.

How the Four Standards Work Together

The typical ISMS workflow follows this logical sequence:

  1. Use ISO/IEC 27000 to unify terminology and understand the overall ISMS concept.

  2. Build the management system framework following ISO/IEC 27001 requirements.

  3. Perform risk assessment and risk evaluation using ISO/IEC 27005.

  4. Select appropriate security controls from ISO/IEC 27002 to treat unacceptable risks.

  5. Document selected controls in the Statement of Applicability and operate the ISMS.

Conclusion

ISO/IEC 27000, 27001, 27002 and 27005 each occupy a distinct position in the ISMS ecosystem. ISO/IEC 27000 is the terminology foundation; ISO/IEC 27001 is the certifiable management system requirement; ISO/IEC 27002 is the control best practice library; ISO/IEC 27005 is the risk management playbook. Organisations aiming for ISO 27001 certification must combine all four perspectives. Without ISO/IEC 27005, teams may blindly apply controls from ISO/IEC 27002 without risk justification, which violates the risk-based principle of ISMS and may fail external audits.