Skip to content

Structure of the ISO 27000 domain

Object and subtypes

Scope objects

  • Organizations: To map the organization with the most important master data.
  • ISMS scopes: ISMS scopes for defining which areas of a company are affected by the implementation and application of the ISMS.
  • External service providers: Are considered separately as external institutions or organizations in order to map the special outsourcing requirements.
  • Scopes (general): To map other objects of consideration, such as projects or interest groups.

Process objects

  • Business processes: To document the core processes and other supporting processes.

Asset objects

  • Assets: Information assets that are taken into account in the ISMS.

Person objects

  • Persons: Persons (groups) or roles.

Incident objects

  • Information security incidents: For the documentation of incidents/occurrences.

Document objects

  • Documents: For recording and linking documents.
  • Records: Storage of documents to be used as evidence.

Control objects

  • Requirements: Requirements of DIN ISO/IEC 27001:2024 from the management framework.
  • Security measures: Security measures from Annex A of DIN ISO/IEC 27001:2024.
  • Control groups: All mitigating measures for a risk object.

Scenarios

  • Scenarios: Scenarios for use in the risk analysis.

Catalog

In addition to scenarios based on threats and vulnerabilities of ISO/IEC 27005:2022, the catalog also provides requirements of DIN ISO/IEC 27001:2024 from the management framework and security measures from Appendix A. Sample objects for documents and records are also included.

Profiles

The profile Risk profile according to DIN ISO/IEC 27001 provides an organization with sample objects for mapping an ISMS according to DIN ISO/IEC 27001 including a prepared risk analysis. Scenarios based on threats and vulnerabilities of ISO/IEC 27005:2022 are linked to relevant example assets and the management requirements as well as the Annex A requirements of DIN ISO/IEC 27001:2024 for risk treatment are taken into account.

Reports

The ISO 27000 domain provides the following reports

  • Statement of applicability: Lists all security measures from Annex A of DIN ISO/IEC 27001 and describes whether they are applied, excluded or partially implemented as well as a statement of applicability or non-applicability.

  • Inventory: An overview of all relevant assets.

Risk definition

The standard risk definition ISO risk analysis (ISORA) contains the protection objectives of confidentiality, integrity and availability.