NF ISO/IEC 27000
Information technology - Security techniques - Information security management systems - Overview and vocabulary
ISO/IEC 27000:2009 provides an overview of information security management systems, which form the subject of the information security management system (ISMS) family of standards, and defines related terms. As a result of implementing ISO/IEC 27000:2009, all types of organization (e.g. commercial enterprises, government agencies and non-profit organizations) are expected to obtain: an overview of the ISMS family of standards; an introduction to information security management systems (ISMS); a brief description of the Plan-Do-Check-Act (PDCA) process; and an understanding of terms and definitions in use throughout the ISMS family of standards. The objectives of ISO/IEC 27000:2009 are to provide terms and definitions, and an introduction to the ISMS family of standards that: define requirements for an ISMS and for those certifying such systems; provide direct support, detailed guidance and/or interpretation for the overall Plan-Do-Check-Act (PDCA) processes and requirements; address sector-specific guidelines for ISMS; and address conformity assessment for ISMS.
ISO/IEC 27000:2009 provides an overview of information security management systems, which form the subject of the information security management system (ISMS) family of standards, and defines related terms. As a result of implementing ISO/IEC 27000:2009, all types of organization (e.g. commercial enterprises, government agencies and non-profit organizations) are expected to obtain:
- an overview of the ISMS family of standards;
- an introduction to information security management systems (ISMS);
- a brief description of the Plan-Do-Check-Act (PDCA) process; and
- an understanding of terms and definitions in use throughout the ISMS family of standards.
The objectives of ISO/IEC 27000:2009 are to provide terms and definitions, and an introduction to the ISMS family of standards that:
- define requirements for an ISMS and for those certifying such systems;
- provide direct support, detailed guidance and/or interpretation for the overall Plan-Do-Check-Act (PDCA) processes and requirements;
- address sector-specific guidelines for ISMS; and
- address conformity assessment for ISMS.
Le présent document décrit une vue d''ensemble et le vocabulaire des systèmes de management de la sécurité de l''information, qui constituent l''objet de la famille de normes du SMSI, et définit les termes et les définitions qui s''y rapportent. Il est applicable à tous les types et à toutes les tailles d''organisations (par exemple entreprises commerciales, organisations publiques, organisations à but non lucratif).
- Avant-proposiv
-
0 Introductionv
-
1 Domaine d'application1
-
2 Termes et définitions1
-
3 Systèmes de management de la sécurité de l'information1
-
3.1 Introduction6
-
3.2 Qu'est ce qu'un SMSI ?6
-
3.3 Approche processus8
-
3.4 Raisons pour lesquelles un SMSI est important8
-
3.5 Établissement, surveillance, mise à jour et amélioration d'un SMSI9
-
3.6 Facteurs critiques de succès du SMSI11
-
3.7 Avantages de la famille des normes SMSI11
-
4 La famille des normes SMSI12
-
4.1 Informations générales12
-
4.2 Normes décrivant une vue d'ensemble et une terminologie13
-
4.3 Normes spécifiant des exigences14
-
4.4 Normes décrivant des lignes directrices générales15
-
4.5 Normes décrivant des lignes directrices propres à un secteur16
- Annexe A (informative) Expressions verbales pour exprimer des dispositions17
- Annexe B (informative) Termes classés par catégories18
- Bibliographie20
To comply with a standard, you need to quickly understand its issues in order to determine its impact on your activity.
The Requirements department helps you quickly locate within the normative text:
- mandatory clauses to satisfy,
- non-essential but useful clauses to know, such as permissions and recommendations.
The identification of these types of clauses is based on the document "ISO/IEC Directives, Part 2 - Principles and rules of structure and drafting of ISO documents" as well as on a constantly enriched list of verbal forms.
With Requirements, quickly access the main part of the normative text!

- The UPSELL service allows you to easily update one of your standards.
- With a single click, add a new language, the Requirements or Redline+ service and add one or more additional users.
- Whether you are in the process of acquiring a standard or it is already available in your personal space, the UPSELL service is available at every stage to help you understand it and implement it within your organization.
COBAZ is the simple and effective solution to meet the normative needs related to your activity, in France and abroad.
Available by subscription, CObaz is THE modular solution to compose according to your needs today and tomorrow. Quickly discover CObaz!
Request your free, no-obligation live demo
I discover COBAZ