Skip to content
Ekontrol
Back to Resources

International Information Security Standards: Mapping the ISO 2700x Family and ISO 22301 (2026)

International information security standards mapped: the ISO 2700x family (ISO/IEC 27001, 27002, ISO 27701) plus ISO 22301. Learn which standard does what.

Published August 4, 202613 min read
International information security standards: a map of the ISO 2700x family and ISO 22301

International Information Security Standards: Why You Need a Map

When a company first gets serious about information security, because a client asks for it, a tender requires it, or plain common sense demands it, it almost immediately drowns in numbers. ISO/IEC 27001, ISO/IEC 27002, ISO 27701, ISO 22301, and alongside them 27005, 27017, 27018. At first glance, international information security standards look like a catalog you can't navigate without a guide.

In reality it isn't a chaotic list but a family with fairly simple logic. One standard sets the rules and grants a certificate. Another explains how to meet those rules in practice. A third handles privacy, and a fourth makes sure the business survives a disruption and keeps running. Once you can see who's responsible for what, the whole structure stops being intimidating.

This article is exactly that kind of map. We'll walk through the main standards of the ISO 2700x family, add ISO 22301 on business continuity, and show how they fit together. And if after the map you'd rather jump straight to practice, our complete guide to ISO/IEC 27001 breaks down the anchor standard step by step, starting with where to begin implementation.

ISO, IEC, and DSTU: Why the Names Carry So Many Abbreviations

A label like ISO/IEC 27001:2022 reads more easily than it looks. ISO is the International Organization for Standardization, IEC is the International Electrotechnical Commission, and they publish most security standards jointly, hence the 'ISO/IEC.' Standards with only ISO in the name, like ISO 22301, are run by a different technical committee. The number after the colon is the year of the current edition. And DSTU ISO/IEC 27001:2023 is the official Ukrainian edition of the very same standard, identical in content to the original.

ISO/IEC 27001: The Anchor of the Whole Family

If you remember only one number from this whole article, make it 27001. ISO/IEC 27001 is the only standard in this family a company can actually be certified against: after an independent audit, you receive a globally recognized certificate. Every other standard revolves around it in one way or another.

What exactly does it require? Building an information security management system (ISMS): a set of processes, policies, and owners that keeps the risks to your data under control. The standard deliberately doesn't dictate technologies and never says 'install this particular antivirus.' It requires something else: define what you're protecting, assess the risks, and choose measures to match them. That's why 27001 works equally well for a 20-person IT company and a large bank.

The security measures themselves live in Annex A, which in the 2022 edition holds 93 controls grouped into four themes: organizational, people, physical, and technological. Ukraine has an identical national edition, DSTU ISO/IEC 27001:2023, so certifying against the Ukrainian version is no different in substance. The full path to a certificate is laid out in our guide to ISMS certification; here only one thing matters: 27001 is the front door, not the whole building. For companies unsure where to start, we recommend looking first at ISO/IEC 27001 certification.

ISO/IEC 27002: A Controls Reference, Not a Certificate

The second most recognizable number, ISO/IEC 27002, is confused with 27001 more often than almost anything. The difference is simple but fundamental: ISO/IEC 27002 is not a certification standard. You can't be audited against it and receive a certificate. It's a reference of good practice that explains in detail how to implement those same 93 controls from Annex A.

Think of the pair this way. 27001 says 'assess your risks and choose the controls you need,' and lists those controls by short name. 27002 takes each one and expands it into several paragraphs: what it's for, how to configure it, what to watch out for. That's why in practice the two documents are almost always read together, one setting the requirement and the other suggesting how to meet it.

Hence the classic mistake in tenders and email threads: the phrase 'ISO 27002 certification' makes no sense. You certify against 27001. With 27002 you train, you benchmark, you build internal guidance. If someone promises you an 'ISO 27002 certificate,' that's a good reason to ask what they actually mean.

What You Can Certify Against, and What You Can't

The 'certifiable versus not certifiable' confusion costs companies time and money. Remember the line: you can be certified against ISO/IEC 27001, ISO 22301, and, since 2025, ISO 27701. The standards ISO/IEC 27002, ISO/IEC 27005, 27017, and 27018 are guidance: you build and improve your system with them, but they don't grant a certificate. If a supplier offers you 'ISO 27002 certification,' they either misspoke or don't really know the subject. This small distinction saves you from false expectations right at the start.

ISO 27701: The Standard for Privacy and Personal Data

What if a company's main risk isn't abstract 'information' but the specific personal data of its customers? That's what ISO 27701 is for: a privacy management standard, or PIMS (Privacy Information Management System). It answers not 'how do I protect data from a breach' but the broader question of how to handle personal data properly in the first place: collecting, storing, transferring, deleting.

Here's a change worth knowing about for anyone choosing a standard right now. Until 2025, ISO 27701 existed only as an extension to ISO/IEC 27001, and certifying against it separately was impossible. The ISO/IEC 27701:2025 edition, published on 14 October 2025, made it a standalone standard. A company can now obtain a PIMS certificate even without ISO/IEC 27001 certification, for instance when privacy matters to it more than anything else.

The new edition also tidied up the controls: instead of more than 150 requirements scattered through the 2019 text, there are now 78 controls in three clear tables, for the data controller, the processor, and shared cases. It added a direct mapping to GDPR articles, which noticeably simplifies conversations with European partners and auditors. Companies holding a valid certificate under the old edition have until October 2028 to transition. The link between Ukraine's personal data law, GDPR, and these standards is a big topic in its own right; here it's enough to keep the main point in mind: 27701 is the one responsible for privacy.

ISO 22301: Business Continuity Alongside Security

The last major standard on our map sits slightly apart from the 2700x family, yet it's closely tied to it. ISO 22301 is the standard for business continuity management (BCMS). It answers the question 27001 leaves open: what to do when your defenses are breached after all, or when something happens outside cybersecurity entirely, such as a fire, a blackout, shelling, or the failure of a key supplier.

In practice, 22301 requires you to analyze which processes are critical to the company, how quickly they must be restored after a stoppage, and what staff actually do in the first hours of a disruption. That turns a chaotic 'we'll manage somehow' into a plan written and tested in advance, with owners, backup channels, and a clear sequence of steps.

Note the label: here it's 'ISO,' not 'ISO/IEC.' That's because 22301 is run by a different technical committee, one for security and resilience, rather than the joint ISO and IEC committee. For a business it changes nothing: the standard is certified through an independent audit, just like 27001.

For Ukrainian companies, ISO 22301 has turned from a purely 'Western' topic into a very practical one. When the power goes out on a schedule and critical infrastructure is under attack, the ability to keep working despite disruptions is no longer a luxury but a condition of survival. That's why ISO 22301 and ISO/IEC 27001 are often implemented together: the first holds continuity, the second holds security. Between them they cover both the 'we got hacked' scenario and the 'we physically can't work' one.

Not Sure Which Standard to Start With?

For most companies the entry point is ISO/IEC 27001: it sets the framework the other standards in the family rely on. Our complete guide walks you through the requirements, the ISMS, and the cost and timeline of certification in Ukraine, step by step.

Complete guide to ISO/IEC 27001

Supporting Standards: 27000, 27005, 27017, 27018

The 2700x family is much larger than its four main numbers: it holds more than a dozen documents. You don't need to know them all by heart, but it helps to recognize the ones that come up most often. All of them are guidance, not certificates.

  • ISO/IEC 27000 is the glossary and general introduction to the whole family. It explains the terms and shows how the standards relate to one another. It's available for free, so it's a convenient place to start.
  • ISO/IEC 27005 is guidance on information security risk management. It's the detailed answer to 27001's 'assess your risks' requirement: methods, approaches, and examples for anyone doing an assessment for the first time.
  • ISO/IEC 27017 is security guidance for cloud services. It matters to anyone keeping data or a product in the cloud, which today means most companies.
  • ISO/IEC 27018 covers protecting personal data in the public cloud. It often goes hand in hand with 27017 and 27701 when customer privacy in cloud services is at stake.

The logic is the same as with 27002: the main standard sets the requirement, and the supporting standards show how to meet it in a specific situation, whether that's risk, the cloud, or privacy. Here's how it all looks side by side.

StandardWhat it coversCertificationCurrent edition
ISO/IEC 27001ISMS requirements: managing information securityYes, via audit2022 (DSTU ISO/IEC 27001:2023)
ISO/IEC 27002Catalog and description of 93 security controlsNo, guidance2022
ISO 27701Privacy management (PIMS), personal dataYes, since October 2025ISO/IEC 27701:2025
ISO 22301Business continuity (BCMS)Yes, via audit2019

How to Choose an Information Security Standard for Your Situation

Now the most practical question: which of these do you actually need? There's no universal answer, but there is a simple selection logic.

For the vast majority of companies, the starting point is ISO/IEC 27001. It provides the framework without which the other standards hang in the air: first you put general security in order, then you build privacy or continuity on top as needed. So even if you're specifically interested in 27701 or 22301, the road usually starts the same way, with a 27001-style risk assessment.

After that, it goes by your main risk. If you're an IT or SaaS company processing personal data of EU customers, it makes sense to reinforce the system with 27701. If your business can't afford to stop, think critical infrastructure, manufacturing, or services running through outages, then ISO 22301 is next. And 27002 and 27005 don't need separate 'implementation': you use them inside a 27001 project when it comes to choosing and configuring specific controls.

In short: start with 27001 as the common denominator, and add the specialized standards for a specific need. That's exactly why our guide to ISO/IEC 27001 certification is the logical next stop after this map.

How Ekontrol Helps You Choose Security Standards

In practice, most companies come to us with exactly this question, 'which standard do we need,' and that's the right first step. Ekontrol supports preparation for ISO/IEC 27001, ISO 27701, and ISO 22301 as a single information security practice, so we start not by selling a particular certificate but by unpacking your situation: what data you process, what your clients and contracts require, and where your main risk actually lies.

Next comes a diagnostic of your current state, the choice of the right set of standards, and support all the way to the certification audit. If you already have one system, adding a second standard turns out faster and cheaper: ISO/IEC 27001, ISO 27701, and ISO 22301 are built on the shared structure of clauses 4 to 10, so most of the management processes carry over without rework. Our certification preparation services cover the whole path, from the first assessment to the audit.

If you're still not sure where to begin, there are two simple options: read the detailed guide to ISO/IEC 27001 to get to grips with the anchor standard, or get in touch with the Ekontrol team right away to discuss your situation. We've worked as a Bureau Veritas partner in Ukraine since 2014.

FAQ: Questions About International Information Security Standards

The questions people most often ask when they first try to work out how international information security standards differ and which one they need right now.

Tags