Overview
ISO/IEC TR 27103:2018 - "Information technology - Security techniques - Cybersecurity and ISO and IEC Standards" is a technical report that provides guidance on how to leverage existing ISO and IEC standards when building or operating a cybersecurity framework. It explains a risk-based, prioritized, outcome-focused approach and maps high-level cybersecurity objectives to existing information‑security standards such as ISO/IEC 27001 and the ISO/IEC 27000 family. The report is intended to help organizations define current and target cybersecurity states, prioritize improvements, and communicate risk across stakeholders.
Key Topics and Requirements
- Risk-based approach: Emphasizes using a risk-based method to prioritize cybersecurity investments, measure impact over time, and remain flexible in a changing threat landscape.
- Cybersecurity framework structure: Describes a layered framework of Functions → Categories → Sub-categories, enabling both executive-level planning and operational implementation.
- Five core functions: Defines the strategic functions that a cybersecurity framework should cover:
- Identify - understand assets, business context and risks
- Protect - implement safeguards to limit impact
- Detect - identify cybersecurity events promptly
- Respond - contain and mitigate detected events
- Recover - restore capabilities and services post‑event
- Activities of a cybersecurity programme: Guidance on describing current status, defining target state, identifying improvement opportunities, assessing progress, and communicating with internal and external stakeholders.
- Stakeholder involvement: Stresses roles beyond technical teams - including top management and external partners - to manage many‑to‑many interactions and shared risks.
- Informative annexes: Annex A breaks down sub-categories and aligns them to standards; Annex B provides principles and essentials for top management oversight.
- Normative status: The report contains no normative references - it is guidance to help apply existing standards rather than add prescriptive requirements.
Practical Applications and Who Should Use It
- CISOs and security leaders: To align cybersecurity strategy with business risk, prioritize investments, and communicate outcomes to executives.
- Security architects and practitioners: To map operational controls and technical activities to recognized framework functions and sub‑categories.
- Auditors and compliance teams: To assess maturity and demonstrate that cybersecurity practices are grounded in established ISO/IEC standards.
- Policy makers and consultants: To design sector or organization‑specific cybersecurity programmes that leverage ISO/IEC guidance.
Practical uses include framework adoption, ISMS integration (ISO/IEC 27001), gap analysis, vendor and third‑party risk discussions, and program reporting.
Related Standards (applicable)
- ISO/IEC 27001 (Information Security Management System - ISMS)
- ISO/IEC 27000 series (terminology and foundational concepts)
- Other ISO/IEC security techniques standards developed by JTC 1/SC 27
Keywords: ISO/IEC TR 27103:2018, cybersecurity framework, risk-based approach, ISMS, ISO standards, cyber risk management, Identify Protect Detect Respond Recover.