The wider ISO/IEC 27000 family and adjacent ISO standards that extend, refine, or run parallel to 27001. Plus the non-ISO frameworks that overlap heavily (NIST CSF, SOC 2, PCI DSS, Cyber Essentials, CSA Cloud Controls Matrix). When 27001 is the spine, the family is the rib cage.
The ISO/IEC 27000 series
Core / foundational
- ISO/IEC 27000:2018 โ Overview and vocabulary. Free from iso.org. Definitions used across the family.
- ISO/IEC 27001:2022 โ ISMS requirements. The certifiable standard.
- ISO/IEC 27002:2022 โ Information security controls (implementation guidance). The companion handbook to Annex A.
Implementation and operations
- ISO/IEC 27003:2017 โ ISMS implementation guidance.
- ISO/IEC 27004:2016 โ Monitoring, measurement, analysis and evaluation.
- ISO/IEC 27005:2022 โ Information security risk management. Recommended companion to Cl 6.1.2-6.1.3.
- ISO/IEC 27007:2020 โ Management systems auditing guidelines.
- ISO/IEC 27008:2019 โ Assessment of information security controls.
- ISO/IEC 27014:2020 โ Governance of information security.
Certification bodies and competence
- ISO/IEC 27006:2015 + amendments โ Requirements for ISO 27001 certification bodies.
- ISO/IEC 27021:2017 โ Competence requirements for ISMS professionals.
Sector and topic extensions
- ISO/IEC 27010:2015 โ Inter-sector and inter-organizational communications.
- ISO/IEC 27011:2016 โ Telecommunications.
- ISO/IEC 27017:2015 โ Cloud-services controls. Customer-side and provider-side extensions of 27002.
- ISO/IEC 27018:2019 โ PII protection in public clouds acting as PII processors. Complements GDPR Article 28 processor obligations.
- ISO/IEC 27019:2017 โ Energy utility industry process control systems.
- ISO 27799:2016 โ Health informatics.
Business continuity and resilience
- ISO/IEC 27031:2011 โ ICT readiness for business continuity. Revision in progress.
- ISO 22301:2019 โ Business continuity management systems (sibling to 27001 under Annex SL).
Incident management and forensics
- ISO/IEC 27035:2023 (multi-part) โ Information security incident management. Part 1 principles, Part 2 plan/prepare, Part 3 ICT incident response, Part 4 coordination.
- ISO/IEC 27037:2012 โ Digital evidence: identification, collection, acquisition, preservation.
- ISO/IEC 27038:2014 โ Redaction of digital information.
- ISO/IEC 27041:2015 โ Investigation suitability assurance.
- ISO/IEC 27042:2015 โ Investigation analysis and interpretation.
- ISO/IEC 27043:2015 โ Investigation principles and processes.
Storage, networking, application security
- ISO/IEC 27033 (multi-part) โ Network security.
- ISO/IEC 27034 (multi-part) โ Application security.
- ISO/IEC 27040:2024 โ Storage security.
Supplier relationships
- ISO/IEC 27036 (multi-part) โ Supplier relationships. Part 1 overview, Part 2 requirements, Part 3 ICT supply chain, Part 4 cloud-specific.
Privacy
- ISO/IEC 27701:2019 โ Privacy Information Management System (PIMS). Extends 27001 / 27002 with privacy-specific requirements. GDPR-aligned.
- ISO/IEC 29100:2024 โ Privacy framework.
- ISO/IEC 29151:2017 โ Code of practice for PII protection.
AI security and privacy
- ISO/IEC 42001:2023 โ AI management system (AIMS). The 27001-equivalent for AI governance. Certifiable.
- ISO/IEC 23894:2023 โ AI risk management guidance.
- ISO/IEC 27090 (in development, draft 2025) โ AI security.
- ISO/IEC 27091 (in development, draft 2025) โ AI privacy.
Adjacent non-ISO frameworks
US-origin
- NIST Cybersecurity Framework 2.0 (February 2024) โ voluntary outcome-oriented framework. Functions: Govern (new in 2.0), Identify, Protect, Detect, Respond, Recover. Maps to ISO 27002:2022 via cyberproperty attribute axis. Non-certifiable. Widely adopted as the implementation reference even in ISO 27001 shops.
- NIST SP 800-53 Rev. 5 (September 2020 + updates) โ federal information systems controls catalogue. Mapping to ISO 27001 / 27002 published by NIST.
- NIST SP 800-171 Rev. 3 (2024) โ protecting CUI in non-federal systems. Required for DoD contractors via CMMC.
- NIST AI Risk Management Framework 1.0 (January 2023) + Generative AI Profile (July 2024).
- CMMC 2.0 โ Cybersecurity Maturity Model Certification, three levels. US DoD supply chain.
- SOC 2 (AICPA) โ attestation framework with Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type 1 (point-in-time) vs Type 2 (period coverage, typically 6-12 months). US procurement default.
- HITRUST CSF โ healthcare-origin, broadened. Combines HIPAA, NIST, ISO 27001, PCI DSS, others. US healthcare procurement.
- FedRAMP โ US federal cloud authorization. Three impact levels.
- CIS Critical Security Controls v8 (2021) โ 18 controls, 153 safeguards. Prescriptive technical baseline. Mapping to ISO 27002 maintained.
UK / EU origin
- UK Cyber Essentials / Cyber Essentials Plus โ NCSC. Five technical control areas (firewalls, secure configuration, user access control, malware protection, security update management). Self-assessed (Cyber Essentials) or externally audited (Plus). Common UK government supplier requirement.
- UK NIS Regulations (2018) / EU NIS2 Directive (2022/2555) โ operators of essential services. Member-state transposition completed late 2024 / early 2025. Enforcement ramping.
- EU GDPR (2016/679) โ privacy. ISO 27001 + 27701 are common technical-and-organisational measures evidence.
- EU DORA (2022/2554) โ Digital Operational Resilience Act for financial services. Applicable since 17 January 2025.
- EU AI Act (2024/1689) โ risk-tiered AI regulation. General-purpose AI obligations from 2 August 2026; high-risk system obligations from 2 August 2027. ISO 42001 alignment likely.
- EU Cyber Resilience Act (2024/2847) โ digital products cybersecurity, mandatory from late 2027.
- TISAX โ Trusted Information Security Assessment Exchange. Automotive-sector adaptation of ISO 27001, German-origin (VDA). Required by major German automakers.
Industry-specific
- PCI DSS v4.0 (March 2022, mandatory March 2025) โ payment card industry. Prescriptive.
- CSA Cloud Controls Matrix v4 โ Cloud Security Alliance. Maps to multiple frameworks. STAR Registry for cloud-provider attestation (3 levels).
- HIPAA Security Rule (US healthcare) โ administrative, physical, technical safeguards for ePHI.
- FFIEC (US financial) โ federal regulator cybersecurity guidance.
- NYDFS 23 NYCRR 500 (NY financial services) โ explicit cyber requirements.
Application / development security
- OWASP Top 10 โ web application security risks.
- OWASP API Security Top 10 โ API-specific risks.
- OWASP LLM Top 10 (2023, 2024 revision) โ LLM-integrated application risks. De facto AI-app-security taxonomy.
- OWASP ASVS โ application security verification standard.
- OWASP SAMM โ software assurance maturity model.
- BSIMM โ Building Security In Maturity Model.
- MITRE ATT&CK โ adversary tactics and techniques.
- MITRE D3FEND โ defensive countermeasures.
- MITRE ATLAS โ adversarial threat landscape for AI systems.
- SLSA โ Supply-chain Levels for Software Artifacts.
Mapping crosswalks
Common combinations and where to find mappings:
- ISO 27001 โ NIST CSF 2.0 โ ISO/IEC 27002:2022 attribute axis includes NIST CSF function alignment; NIST publishes a crosswalk.
- ISO 27001 โ SOC 2 โ published mapping (e.g., AICPA's TSC mapping document, Schellman / A-LIGN combined-audit documentation).
- ISO 27001 โ PCI DSS v4 โ PCI Council publishes mappings.
- ISO 27001 โ CIS CSC v8 โ CIS-maintained mapping.
- ISO 27001 โ HIPAA โ HITRUST CSF effectively bridges; direct mapping documents exist.
- ISO 27001 โ ISO 42001 โ bridge guidance maturing; ISO/IEC JTC 1/SC 42 publishing aligned implementation notes.
Buyer-facing implication: a single set of controls implementation can satisfy multiple frameworks. The audits remain separate; the underlying work overlaps 70-90%. Combined-audit certification bodies (Schellman, A-LIGN, BSI, others) offer single-engagement multi-cert paths.
Common implementation stacks
Three patterns common in practice:
- EU SaaS pattern: ISO 27001 + ISO 27701 + (optional) ISO 27017 + (optional) ISO 27018. GDPR-aligned.
- US SaaS pattern: SOC 2 Type 2 + (optional) ISO 27001 + (optional) HIPAA / FedRAMP / state-specific.
- AI-native pattern (emerging): ISO 27001 + ISO 42001 + (optional) ISO 27701. AI Act 2026-2027 ramp will accelerate adoption.
SRE and AI-agent fit notes
- ISO 42001 is the most relevant adjacent standard for AI-system operators. Sibling structure to 27001 (Annex SL), with AI-specific controls. Combined certification path emerging through 2025-2026.
- ISO 27017 for cloud-customer responsibilities, especially when relying on cloud-hosted model APIs.
- ISO 27018 for cloud-PII-processor relationships. Applicable when the org acts as a controller using a vendor as processor.
- ISO 27036-3 for ICT supply chain โ relevant to AI-coding-tool, model-vendor, vector-DB-vendor selection and oversight.
- MITRE ATLAS and OWASP LLM Top 10 as the operational threat taxonomies that flow into ISO 27001 Cl 6.1.2 risk inputs and A.5.7 threat intelligence.