Overview - ISO/IEC TS 27100:2020 (Cybersecurity - Overview and concepts)
ISO/IEC TS 27100:2020 is a technical specification that provides a concise overview of cybersecurity and the core concepts organizations need to understand cyber risk. Rather than prescribing controls, this ISO/IEC TS establishes the context of cyberspace and cybersecurity, clarifies how cybersecurity relates to information security and ISMS, and defines key terms (e.g., cyberspace, cyber threat, cyber incident). It is applicable to all types and sizes of organizations - from SMEs to governments and critical infrastructure operators.
Key topics and concepts
The document covers foundational topics useful for building a cybersecurity program and for aligning with other standards:
- Definitions and vocabulary - clear terms for cyber attack, cybersecurity event/incident, cyberspace, cyber threat and risk (aligned with ISO/IEC 27000 family).
- Cyberspace characteristics - borderless, interconnected environment with asymmetric and near‑instant impacts.
- Relationship to information security and ISMS - differences in scope and objectives; how ISMS supports cybersecurity and how cyberspace introduces additional risk sources.
- Risk management in a cyber context - threat and risk identification tailored to cyberspace.
- Cyber threats by sector - considerations for business organizations, industrial control systems, products/services/supply chains, telecoms/ISPs, public authorities, critical infrastructure and individuals.
- Incident management and coordination - incident detection, organizational response, cross‑organizational coordination and supplier technical support.
- Framework and safety considerations - interaction between cybersecurity frameworks, safety, and cyber insurance.
- Layered model of cyberspace - conceptual models (informative annex) to visualize relationships among networks, services, people and processes.
Practical applications - who uses this standard
ISO/IEC TS 27100:2020 is a reference document intended for those who need conceptual clarity and context before selecting or implementing controls:
- CISOs, security leaders and risk managers establishing cybersecurity strategy or aligning programs to international best practice.
- ISMS implementers and auditors who need to distinguish information security and cybersecurity scopes.
- Policy makers and regulators developing cyber policy, sectoral guidance or national strategies.
- Product and service suppliers, system integrators and telecommunication providers assessing supply‑chain and service risks.
- Operators of critical infrastructure, industrial control systems and public authorities planning incident response and cross‑organizational coordination.
Related standards
ISO/IEC TS 27100:2020 is a practical, standards‑based primer for organizations that need a clear conceptual foundation in cybersecurity and cyber risk management.