Overview
ISO/IEC TS 27110:2021 - Information technology, cybersecurity and privacy protection - Cybersecurity framework development guidelines - gives guidance for developing cybersecurity frameworks. It specifies a minimum set of concepts a framework should use so that different frameworks can be compatible, interoperable and flexible. The technical specification is aimed at cybersecurity framework creators and applies irrespective of organization type, size or sector.
Key topics and technical focus
- Core concepts (Identify, Protect, Detect, Respond, Recover) - The document mandates these five foundational pillars as the minimum conceptual structure for a cybersecurity framework and describes their purpose and scope.
- Identify: scoping the cybersecurity ecosystem - business objectives, assets, stakeholders, governance, supply chain, risk assessment and cyber persona.
- Protect: safeguards and preventative controls - access control, data security, identity and access management, security architecture, maintenance and protective technologies.
- Detect: activities to discover cybersecurity events and anomalous behavior (monitoring, logging, situational awareness).
- Respond: actions to contain and mitigate incidents (incident response planning and coordination).
- Recover: restoration of services and lessons learned to improve resilience.
- Design principles - frameworks should be flexible, compatible and interoperable to allow multiple frameworks to align and be used together.
- Scope and applicability - guidance for creators on granularity, categories and subcategories; allows augmentation to meet stakeholder requirements but sets a common baseline.
- Integration guidance - Annexes offer considerations for creating and integrating frameworks into practice (organizational context, ISMS relationship, and implementation considerations).
Practical applications and target users
- Who uses it: national bodies, industry consortia, government agencies, standards developers, large enterprises and consultants who design, publish or harmonize cybersecurity frameworks.
- How it’s used:
- As a starting template to design a new cybersecurity framework or to align an existing one with international concepts.
- To enable easier communication and interoperability between organizations using different frameworks.
- To guide integration of a cybersecurity framework with an ISMS (e.g., ISO/IEC 27001) without replacing ISMS requirements.
- To support risk management, supply chain security, and cross-organizational cyber resilience efforts.
Related standards
- ISO/IEC 27000 family (overview and vocabulary)
- ISO/IEC 27001 (ISMS requirements) - complementary; ISO/IEC TS 27110 does not supersede ISMS requirements.
- ISO/IEC TS 27100 (Cybersecurity - Overview and concepts)
Using ISO/IEC TS 27110:2021 helps standardize the language and structure of cybersecurity frameworks, making cybersecurity framework development more consistent, interoperable and easier to adopt across sectors.