Primary documents, related standards, named practitioners, and reference resources for the ISO 27001 cluster. Curated reading list, not exhaustive.
Primary normative documents
- ISO/IEC 27001:2022 โ Information security, cybersecurity and privacy protection โ Information security management systems โ Requirements. Published 25 October 2022. Available from iso.org (CHF 124 / ~โฌ130 single-user PDF) and national standards bodies (BSI for UK, DIN for DE, ANSI for US โ typically national-currency equivalent with local annexes).
- ISO/IEC 27002:2022 โ Information security, cybersecurity and privacy protection โ Information security controls. Published February 2022. The control implementation handbook. Necessary companion to 27001.
- ISO/IEC 27000:2018 โ Vocabulary. Free download from iso.org/standard/73906.html. Defines terms used across the 27000 family.
- ISO/IEC 17021-1:2015 โ Conformity assessment โ Requirements for bodies providing audit and certification of management systems. Governs the certification bodies.
- ISO/IEC 27006:2015 + amendments โ Requirements specific to ISO 27001 certification bodies.
Implementation-side standards
- ISO/IEC 27003:2017 โ ISMS implementation guidance.
- ISO/IEC 27004:2016 โ Monitoring, measurement, analysis, and evaluation. Companion to Cl 9.1.
- ISO/IEC 27005:2022 โ Information security risk management. Companion to Cl 6.1.2-6.1.3.
- ISO/IEC 27007:2020 โ Management systems auditing.
- ISO/IEC 27014:2020 โ Governance of information security.
Sector and topic extensions (27k family)
- ISO/IEC 27017:2015 โ Cloud security controls (cloud service customer and provider).
- ISO/IEC 27018:2019 โ Protection of PII in public clouds acting as PII processors.
- ISO/IEC 27019:2017 โ Energy utility industry.
- ISO/IEC 27031:2011 โ ICT readiness for business continuity (rev in progress).
- ISO/IEC 27034:2011-2018 โ Application security (multi-part).
- ISO/IEC 27035:2023 โ Incident management (multi-part: 1 principles, 2 plan/prepare, 3 ICT incident response, 4 coordination).
- ISO/IEC 27036:2014-2022 โ Supplier relationships (multi-part).
- ISO/IEC 27037:2012 โ Digital evidence identification, collection, acquisition, preservation.
- ISO/IEC 27040:2024 โ Storage security.
- ISO/IEC 27701:2019 โ Privacy information management (PIMS), extends 27001 / 27002 for GDPR / privacy.
- ISO/IEC 42001:2023 โ AI management system (AIMS). Sibling standard to 27001 for AI-system governance.
Related but non-ISO frameworks
- NIST Cybersecurity Framework 2.0 (February 2024) โ voluntary US framework. Functions: Govern, Identify, Protect, Detect, Respond, Recover. Maps to ISO 27002:2022 via the cyberproperty attribute axis.
- NIST SP 800-53 Rev. 5 (September 2020 + updates) โ federal information system controls; mapping to ISO 27002 published by NIST.
- NIST AI Risk Management Framework 1.0 (January 2023) + Generative AI Profile (July 2024).
- CIS Critical Security Controls v8 (2021) โ prioritized 18 controls and 153 safeguards. Mapping to ISO 27002 maintained by CIS.
- AICPA SOC 2 Trust Services Criteria (2017, revised 2022) โ US attestation framework.
- PCI DSS v4.0 (March 2022, mandatory March 2025) โ payment card industry data security.
- UK Cyber Essentials / Cyber Essentials Plus (NCSC) โ entry-level UK framework.
- CSA Cloud Controls Matrix v4 โ cloud-specific, maps to multiple frameworks.
- OWASP LLM Top 10 (2023, 2024 revision) โ application-security taxonomy for LLM-integrated systems.
- MITRE ATT&CK / D3FEND โ adversary tactics and defensive countermeasures, useful for risk assessment input under Cl 6.1.2.
- MITRE ATLAS โ adversarial threat landscape for AI systems.
Regulatory and procurement-driver context
- EU GDPR (Reg 2016/679) โ privacy regulation. ISO 27001 + 27701 widely used as defensible technical-and-organisational-measures evidence.
- EU NIS2 Directive (Dir 2022/2555) โ cybersecurity for essential and important entities. Member-state transposition deadlines 17 October 2024; enforcement ramping through 2025-2026. ISO 27001 alignment is a common path.
- EU AI Act (Reg 2024/1689) โ general provisions in force August 2024; high-risk system obligations from 2 August 2026 (general-purpose AI) and 2 August 2027 (most high-risk). ISO 42001 + ISO 27001 will be the implementation default.
- EU DORA (Reg 2022/2554) โ Digital Operational Resilience Act for financial services. In force 17 January 2025. ICT third-party risk management overlaps with ISO 27001 A.5.19-23 / A.8.
- EU Cyber Resilience Act (Reg 2024/2847) โ product cybersecurity for digital products. Adopted October 2024, applicable late 2027.
- UK Data Protection Act 2018 + GDPR-equivalent post-Brexit framework.
- US state privacy laws โ CCPA / CPRA (CA), VCDPA (VA), CPA (CO), CTDPA (CT), UCPA (UT), and the 2024-2025 wave (TX, OR, MT, DE, NH, NJ, MD, others).
Certification bodies (accredited)
UKAS-accredited (UK) and equivalent national accreditation in DE (DAkkS), US (ANAB), and elsewhere:
- BSI Group โ UK origin, global. Publisher of BS 7799 lineage. Volume leader in UK / EMEA.
- DNV โ Norwegian origin, global. Strong in energy, maritime, manufacturing.
- TรV SรD, TรV Rheinland, TรV Nord โ German technical inspection bodies, dominant in DE Mittelstand certification.
- LRQA (formerly Lloyd's Register Quality Assurance) โ global.
- SGS โ Swiss, global. Largest by volume worldwide.
- Bureau Veritas (BV) โ French, global.
- Schellman โ US-origin, growing internationally. Cross-certified for ISO 27001 + SOC 2.
- A-LIGN โ US-origin, similar combined-audit positioning.
- Coalfire โ US-origin, security-specialist.
- ISACA-affiliated bodies โ varying by region.
Accreditation status is checkable via the certification body's listing on UKAS, DAkkS, ANAB, IAS, or the IAF (International Accreditation Forum) member directory.
Named practitioners and reference voices
Standards and audit
- Edward Humphreys โ convenor of the ISO/IEC JTC 1/SC 27/WG 1 (the ISMS working group) for decades; longtime "Mr ISMS." His writing on 27001 evolution is the closest thing to canon.
- Alan Calder โ IT Governance Ltd founder. Practitioner books on ISO 27001 implementation (UK angle). Useful at the start of an implementation, less so for advanced practice.
- Steve Watkins โ IT Governance co-author; auditor perspective.
Risk and threat
- Jack Jones โ FAIR (Factor Analysis of Information Risk) creator. Quantitative risk model that complements Cl 6.1.2's qualitative default.
- Daniel Miessler โ practitioner-side commentary on real-world security maturity vs compliance theatre.
Cloud and modern infrastructure
- The CSA (Cloud Security Alliance) Star Registry team โ Cloud Controls Matrix maintenance.
- Erica Toelle, Andrew Plato, others โ practitioner writing on cloud-native security and ISO 27017 alignment.
AI / agent systems
- Ram Shankar Siva Kumar โ MITRE ATLAS, AI threat modelling.
- Andrej Karpathy, Simon Willison โ practitioner writing on LLM security, prompt injection (Willison coined the term).
- NIST AI Safety Institute team โ ongoing work on the GenAI profile for the AI RMF.
Critical voices
- Bruce Schneier โ long-running critique of compliance theatre vs real security. The position atom's "compliance โ security" position draws on this lineage.
- Adam Shostack โ threat modelling discipline; argues for threat-model-driven security over control-list-driven security.
Reference resources
- iso.org โ official publisher; CHF-priced PDFs.
- bsigroup.com โ BSI Knowledge subscription model for UK/EMEA users.
- NIST CSRC (csrc.nist.gov) โ free NIST publications; mappings to ISO.
- enisa.europa.eu โ EU agency for cybersecurity; threat-landscape reports useful for Cl 6.1.2 input.
- iaf.nu โ International Accreditation Forum directory for verifying certification body accreditation.