ISO 27001 Family and Sector Variants

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

The wider ISO/IEC 27000 family and adjacent ISO standards that extend, refine, or run parallel to 27001. Plus the non-ISO frameworks that overlap heavily (NIST CSF, SOC 2, PCI DSS, Cyber Essentials, CSA Cloud Controls Matrix). When 27001 is the spine, the family is the rib cage.

The ISO/IEC 27000 series

Core / foundational

  • ISO/IEC 27000:2018 โ€” Overview and vocabulary. Free from iso.org. Definitions used across the family.
  • ISO/IEC 27001:2022 โ€” ISMS requirements. The certifiable standard.
  • ISO/IEC 27002:2022 โ€” Information security controls (implementation guidance). The companion handbook to Annex A.

Implementation and operations

  • ISO/IEC 27003:2017 โ€” ISMS implementation guidance.
  • ISO/IEC 27004:2016 โ€” Monitoring, measurement, analysis and evaluation.
  • ISO/IEC 27005:2022 โ€” Information security risk management. Recommended companion to Cl 6.1.2-6.1.3.
  • ISO/IEC 27007:2020 โ€” Management systems auditing guidelines.
  • ISO/IEC 27008:2019 โ€” Assessment of information security controls.
  • ISO/IEC 27014:2020 โ€” Governance of information security.

Certification bodies and competence

  • ISO/IEC 27006:2015 + amendments โ€” Requirements for ISO 27001 certification bodies.
  • ISO/IEC 27021:2017 โ€” Competence requirements for ISMS professionals.

Sector and topic extensions

  • ISO/IEC 27010:2015 โ€” Inter-sector and inter-organizational communications.
  • ISO/IEC 27011:2016 โ€” Telecommunications.
  • ISO/IEC 27017:2015 โ€” Cloud-services controls. Customer-side and provider-side extensions of 27002.
  • ISO/IEC 27018:2019 โ€” PII protection in public clouds acting as PII processors. Complements GDPR Article 28 processor obligations.
  • ISO/IEC 27019:2017 โ€” Energy utility industry process control systems.
  • ISO 27799:2016 โ€” Health informatics.

Business continuity and resilience

  • ISO/IEC 27031:2011 โ€” ICT readiness for business continuity. Revision in progress.
  • ISO 22301:2019 โ€” Business continuity management systems (sibling to 27001 under Annex SL).

Incident management and forensics

  • ISO/IEC 27035:2023 (multi-part) โ€” Information security incident management. Part 1 principles, Part 2 plan/prepare, Part 3 ICT incident response, Part 4 coordination.
  • ISO/IEC 27037:2012 โ€” Digital evidence: identification, collection, acquisition, preservation.
  • ISO/IEC 27038:2014 โ€” Redaction of digital information.
  • ISO/IEC 27041:2015 โ€” Investigation suitability assurance.
  • ISO/IEC 27042:2015 โ€” Investigation analysis and interpretation.
  • ISO/IEC 27043:2015 โ€” Investigation principles and processes.

Storage, networking, application security

  • ISO/IEC 27033 (multi-part) โ€” Network security.
  • ISO/IEC 27034 (multi-part) โ€” Application security.
  • ISO/IEC 27040:2024 โ€” Storage security.

Supplier relationships

  • ISO/IEC 27036 (multi-part) โ€” Supplier relationships. Part 1 overview, Part 2 requirements, Part 3 ICT supply chain, Part 4 cloud-specific.

Privacy

  • ISO/IEC 27701:2019 โ€” Privacy Information Management System (PIMS). Extends 27001 / 27002 with privacy-specific requirements. GDPR-aligned.
  • ISO/IEC 29100:2024 โ€” Privacy framework.
  • ISO/IEC 29151:2017 โ€” Code of practice for PII protection.

AI security and privacy

  • ISO/IEC 42001:2023 โ€” AI management system (AIMS). The 27001-equivalent for AI governance. Certifiable.
  • ISO/IEC 23894:2023 โ€” AI risk management guidance.
  • ISO/IEC 27090 (in development, draft 2025) โ€” AI security.
  • ISO/IEC 27091 (in development, draft 2025) โ€” AI privacy.

Adjacent non-ISO frameworks

US-origin

  • NIST Cybersecurity Framework 2.0 (February 2024) โ€” voluntary outcome-oriented framework. Functions: Govern (new in 2.0), Identify, Protect, Detect, Respond, Recover. Maps to ISO 27002:2022 via cyberproperty attribute axis. Non-certifiable. Widely adopted as the implementation reference even in ISO 27001 shops.
  • NIST SP 800-53 Rev. 5 (September 2020 + updates) โ€” federal information systems controls catalogue. Mapping to ISO 27001 / 27002 published by NIST.
  • NIST SP 800-171 Rev. 3 (2024) โ€” protecting CUI in non-federal systems. Required for DoD contractors via CMMC.
  • NIST AI Risk Management Framework 1.0 (January 2023) + Generative AI Profile (July 2024).
  • CMMC 2.0 โ€” Cybersecurity Maturity Model Certification, three levels. US DoD supply chain.
  • SOC 2 (AICPA) โ€” attestation framework with Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type 1 (point-in-time) vs Type 2 (period coverage, typically 6-12 months). US procurement default.
  • HITRUST CSF โ€” healthcare-origin, broadened. Combines HIPAA, NIST, ISO 27001, PCI DSS, others. US healthcare procurement.
  • FedRAMP โ€” US federal cloud authorization. Three impact levels.
  • CIS Critical Security Controls v8 (2021) โ€” 18 controls, 153 safeguards. Prescriptive technical baseline. Mapping to ISO 27002 maintained.

UK / EU origin

  • UK Cyber Essentials / Cyber Essentials Plus โ€” NCSC. Five technical control areas (firewalls, secure configuration, user access control, malware protection, security update management). Self-assessed (Cyber Essentials) or externally audited (Plus). Common UK government supplier requirement.
  • UK NIS Regulations (2018) / EU NIS2 Directive (2022/2555) โ€” operators of essential services. Member-state transposition completed late 2024 / early 2025. Enforcement ramping.
  • EU GDPR (2016/679) โ€” privacy. ISO 27001 + 27701 are common technical-and-organisational measures evidence.
  • EU DORA (2022/2554) โ€” Digital Operational Resilience Act for financial services. Applicable since 17 January 2025.
  • EU AI Act (2024/1689) โ€” risk-tiered AI regulation. General-purpose AI obligations from 2 August 2026; high-risk system obligations from 2 August 2027. ISO 42001 alignment likely.
  • EU Cyber Resilience Act (2024/2847) โ€” digital products cybersecurity, mandatory from late 2027.
  • TISAX โ€” Trusted Information Security Assessment Exchange. Automotive-sector adaptation of ISO 27001, German-origin (VDA). Required by major German automakers.

Industry-specific

  • PCI DSS v4.0 (March 2022, mandatory March 2025) โ€” payment card industry. Prescriptive.
  • CSA Cloud Controls Matrix v4 โ€” Cloud Security Alliance. Maps to multiple frameworks. STAR Registry for cloud-provider attestation (3 levels).
  • HIPAA Security Rule (US healthcare) โ€” administrative, physical, technical safeguards for ePHI.
  • FFIEC (US financial) โ€” federal regulator cybersecurity guidance.
  • NYDFS 23 NYCRR 500 (NY financial services) โ€” explicit cyber requirements.

Application / development security

  • OWASP Top 10 โ€” web application security risks.
  • OWASP API Security Top 10 โ€” API-specific risks.
  • OWASP LLM Top 10 (2023, 2024 revision) โ€” LLM-integrated application risks. De facto AI-app-security taxonomy.
  • OWASP ASVS โ€” application security verification standard.
  • OWASP SAMM โ€” software assurance maturity model.
  • BSIMM โ€” Building Security In Maturity Model.
  • MITRE ATT&CK โ€” adversary tactics and techniques.
  • MITRE D3FEND โ€” defensive countermeasures.
  • MITRE ATLAS โ€” adversarial threat landscape for AI systems.
  • SLSA โ€” Supply-chain Levels for Software Artifacts.

Mapping crosswalks

Common combinations and where to find mappings:

  • ISO 27001 โ†” NIST CSF 2.0 โ€” ISO/IEC 27002:2022 attribute axis includes NIST CSF function alignment; NIST publishes a crosswalk.
  • ISO 27001 โ†” SOC 2 โ€” published mapping (e.g., AICPA's TSC mapping document, Schellman / A-LIGN combined-audit documentation).
  • ISO 27001 โ†” PCI DSS v4 โ€” PCI Council publishes mappings.
  • ISO 27001 โ†” CIS CSC v8 โ€” CIS-maintained mapping.
  • ISO 27001 โ†” HIPAA โ€” HITRUST CSF effectively bridges; direct mapping documents exist.
  • ISO 27001 โ†” ISO 42001 โ€” bridge guidance maturing; ISO/IEC JTC 1/SC 42 publishing aligned implementation notes.

Buyer-facing implication: a single set of controls implementation can satisfy multiple frameworks. The audits remain separate; the underlying work overlaps 70-90%. Combined-audit certification bodies (Schellman, A-LIGN, BSI, others) offer single-engagement multi-cert paths.

Common implementation stacks

Three patterns common in practice:

  • EU SaaS pattern: ISO 27001 + ISO 27701 + (optional) ISO 27017 + (optional) ISO 27018. GDPR-aligned.
  • US SaaS pattern: SOC 2 Type 2 + (optional) ISO 27001 + (optional) HIPAA / FedRAMP / state-specific.
  • AI-native pattern (emerging): ISO 27001 + ISO 42001 + (optional) ISO 27701. AI Act 2026-2027 ramp will accelerate adoption.

SRE and AI-agent fit notes

  • ISO 42001 is the most relevant adjacent standard for AI-system operators. Sibling structure to 27001 (Annex SL), with AI-specific controls. Combined certification path emerging through 2025-2026.
  • ISO 27017 for cloud-customer responsibilities, especially when relying on cloud-hosted model APIs.
  • ISO 27018 for cloud-PII-processor relationships. Applicable when the org acts as a controller using a vendor as processor.
  • ISO 27036-3 for ICT supply chain โ€” relevant to AI-coding-tool, model-vendor, vector-DB-vendor selection and oversight.
  • MITRE ATLAS and OWASP LLM Top 10 as the operational threat taxonomies that flow into ISO 27001 Cl 6.1.2 risk inputs and A.5.7 threat intelligence.

See also