
ISO/IEC 27000 just got its first major rewrite since 2018, and the timing is not neutral. The sixth edition, published this month, lands only months after the mandatory transition deadline of 31 October 2025, the date by which every organization still certified under ISO/IEC 27001:2013 had to move to the 2022 version or lose certification. Teams that spent the better part of three years migrating to the new control set are now looking at a rewritten front door to the whole standards family, right after they finished renovating the house behind it.
ISO/IEC 27000 is not the standard organizations get certified against. That is ISO/IEC 27001, which specifies the requirements for an information security management system, or ISMS. ISO/IEC 27000 is the overview and vocabulary document underneath it: it explains what an ISMS is, how the family of standards (27001, 27002, and the sector-specific extensions) relates, and gives buyers and implementers the shared concepts everyone else assumes you already have.
The fifth edition, from 2018, leaned heavily on being a terminology reference. The sixth edition shifts the emphasis toward overview and relationships between the documents, according to the publication itself. That sounds like a small editorial choice, but it changes who the document is actually useful for. A terminology-first document serves people who already know they need ISO/IEC 27001 and want the definitions straight. An overview-and-relationships document serves the person one step earlier: the one deciding whether to pursue certification at all, or trying to explain to a board why 27001 and 27002 are not the same thing.
That relationship question is more tangled than it looks from outside the family. ISO/IEC 27001 sets the requirements an ISMS must meet and is the document an auditor certifies against. ISO/IEC 27002 is the companion code of practice: it is where the detailed guidance behind each Annex A control actually lives, and it is not itself certifiable. Beyond those two sit sector-specific extensions built on the same foundation: ISO/IEC 27017 for cloud service security, ISO/IEC 27018 for protecting personal data in public clouds, ISO/IEC 27701 for privacy information management layered on top of an existing ISMS. An organization evaluating a vendor’s security questionnaire, or deciding which of these to pursue, needs the map ISO/IEC 27000 provides before any of the individual documents make sense on their own.
To understand why the timing matters, it helps to recall what changed in the 2022 revision of ISO/IEC 27001, since that is the standard most organizations are actually implementing. The 2013 version listed 114 controls in its Annex A. The 2022 version consolidated these into 93 controls, organized into four themes instead of the previous 14 domains:
| Theme | What it covers |
|---|---|
| Organizational | Policies, roles, supplier relationships, threat intelligence, cloud security |
| People | Screening, awareness and training, remote working, acceptable use, disciplinary process |
| Physical | Secure areas, equipment, media handling, physical entry |
| Technological | Access control, cryptography, logging, monitoring, data masking, secure coding |
The consolidation added several new controls that did not exist in 2013, including threat intelligence, information security for cloud services, and data masking, reflecting how much the operating environment changed in nine years. Certification bodies enforced the 31 October 2025 deadline strictly: organizations that had not completed the transition audit by that date needed a new certification cycle, not an extension.
Three of the four themes are infrastructure: physical security, technical controls, organizational policy. The people theme is different. It is the one built around the assumption that a compliant system still depends on what an individual chooses to do at a keyboard, and it includes controls for security awareness and training, acceptable use of information and assets, and remote working, alongside the disciplinary process for when those controls fail.
Long-running industry breach research has repeatedly found that human action, not just external attack techniques, accounts for a majority of security incidents, whether through misdirected information, misconfiguration, or simple error in what someone sent to whom. ISO/IEC 27001’s people controls exist because the standard’s authors already know this. An auditor reviewing your awareness and training control does not just want a slide deck confirming staff attended a session. A mature implementation shows evidence that the training changes what people actually do when they are about to make a mistake, not only what they can recite afterward.
This is where a written record matters more than a training completion certificate. If your ISMS documentation can show where communication risk actually concentrates, which department, which type of language, whether it is trending down after a training push, that is a materially stronger answer to an auditor’s question than attendance logs alone.
A short way to check where your own evidence stands: for the awareness and training control, do you have anything dated after the training that shows behavior change, or only a record of who sat through the session? For acceptable use, can you point to what actually gets flagged when someone drafts a message that breaches policy, or does the policy exist only as a document staff signed once? For the disciplinary process, is there a pattern of repeat issues by department that would let you act before an incident, or does the process only start after one has already happened? Auditors increasingly ask the second question in each pair, not the first.
VerbaPulse does not certify anything and does not replace the ISMS your organization builds around ISO/IEC 27001. What it does produce is exactly the kind of evidence the people theme’s controls ask for: an anonymized, department-level record of where risky language shows up in email before it sends, and whether that pattern improves over time. It flags a risky phrase, explains why in plain language, and leaves the decision with the person writing, which keeps it a support for the acceptable-use and awareness controls rather than a monitoring system layered on top of them. The audit trail this produces names no individual and stores no message text, only the pattern an auditor actually needs to see. For teams already mapping controls to evidence ahead of a certification or transition audit, that is a real, usable input, not a new obligation to track.
If your organization holds or is pursuing ISO/IEC 27001 certification, do not treat the people theme as the easy quarter of the audit. Ask what evidence currently backs your awareness and training control beyond a log of who attended a session, and whether that evidence would hold up if an auditor asked whether the training actually changed behavior. The sixth edition of ISO/IEC 27000 will not change what you are certified against. It is a good prompt to check whether your evidence for the human-layer controls has kept pace with everything else you migrated in 2025.
If your next surveillance audit is more than a quarter away, that is enough runway to close the gap properly rather than assembling evidence the week before the auditor arrives.
VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.
Up to 10 seats. EUR 120, credited to your plan if you continue.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →