Overview
ISO/IEC TS 33052:2016 is a Technical Specification that defines a Process Reference Model (PRM) for the domain of information security management. The PRM provides a structured process architecture and a catalog of processes described in terms of process purpose, context, outcomes and requirements traceability. The standard maps each process to ISO/IEC 27001 requirements to support consistent definition and assessment of ISMS-related processes. It is intended to facilitate development of a Process Assessment Model (PAM) (see ISO/IEC TS 33072), not to serve as a conformity-audit checklist or an implementation guide.
Key topics and requirements
- Process architecture: a model of related processes that cover information security management activities.
- Process descriptions: each process includes an ID, name, context, purpose, measurable outcomes and links to ISO/IEC 27001 clauses.
- Traceability to ISO/IEC 27001: outcomes are mapped to relevant ISO/IEC 27001 controls and clauses, enabling consistent alignment with ISMS requirements.
- Scope of processes: the PRM covers management, technical and organizational processes (examples from Clause 5):
- ORG.1 Asset management
- TEC.01 Capacity management
- TEC.02 Change management
- TEC.04 Incident management
- COM.11 Risk and opportunity management
- TEC.07 Service continuity management
- ORG.5 Supplier management
- Assessment orientation: structured to support process assessment activities (PAM), consistent with ISO/IEC 330xx series concepts (process capability measurement, assessment conduct).
Practical applications
- Use the PRM as a baseline to define ISMS processes and their expected outcomes when designing or revising information security processes.
- Map internal processes to ISO/IEC 27001 requirements to demonstrate coverage of controls and identify gaps.
- Support development of a Process Assessment Model (PAM) or internal process maturity assessments aligned with the ISO/IEC 33000 series.
- Aid consultants, process architects and security managers in creating consistent process descriptions for governance, risk and compliance purposes.
Who should use this standard
- ISMS designers and information security managers
- Process assessment model developers and assessors
- Security consultants and internal audit teams who need a structured PRM for assessments or process alignment
- Service providers defining security-related process architectures
Related standards
- ISO/IEC 27001:2013 (ISMS requirements)
- ISO/IEC 33001 / 33002 / 33004 / 33020 (process assessment family)
- ISO/IEC TS 33072 (PAM development)
- ISO/IEC TR 24774 (guidance on related process/content)
Keywords: ISO/IEC TS 33052, process reference model, PRM, information security management, ISMS, ISO/IEC 27001, process assessment model, PAM, asset management, incident management, risk management.