ISO 27001 Clause 3 Terms and definitions

by Maya G

Clause 3 of ISO 27001 provides a list of terms and definitions used in the standard. These terms and definitions are used throughout the document to ensure that there is a clear and consistent understanding of the concepts and requirements of the standard.

Here are some key terms and definitions from ISO 27001 Clause 3:

  1. Asset: Anything that has value to the organization, including information and information systems.
  2. Confidentiality: The property that information is not made available or disclosed to unauthorized individuals, entities, or processes.
  3. Integrity: The property that information is accurate and complete and that it has not been modified or destroyed in an unauthorized or accidental manner.
  4. Availability: The property of being accessible and usable upon demand by an authorized entity.
  5. Information security: Preservation of confidentiality, integrity, and availability of information.
  6. Information security management system (ISMS): A systematic approach to managing sensitive company information so that it remains secure.
  7. Risk: The likelihood of a threat exploiting a vulnerability and the resulting impact on an asset.
  8. Risk assessment: The process of identifying risks to the confidentiality, integrity, or availability of information and evaluating the potential impact of those risks.
  9. Risk treatment: The process of selecting and implementing measures to modify risk.
  10. Statement of applicability: A document that specifies the controls that an organization has implemented to address the risks identified during the risk assessment process.

By providing these terms and definitions, ISO 27001 ensures that there is a common understanding of the concepts and requirements used in the standard, enabling organizations to effectively implement an ISMS that addresses the risks to their information assets.

ISO 27001, ISO 27001 Documentation Toolkit

Implement ISO Faster with a Complete Documentation System

You're currently viewing a single template. Most ISO implementations require a complete set of policies, procedures, and records. Choose what fits your needs.
BEST FOR single ISO STANDARD

ISO Toolkit for Your Standard

Audit ReadyToolkits

Pick your toolkit from 8 ready-to-use ISO toolkits available: ISO 27001, 9001, 14001, 45001, 22301, 20000, and 42001 (AI Governance).

✔ Complete ISO documentation framework
✔ Policies, procedures, templates, and records
✔ Risk management & internal audit templates
✔ Management Review and Nonconformance
✔ ISO Standard Mapped Implementation Plan

💡 All toolkits come with instant download, one-time payment, and unlimited email & chat support.

View ISO Toolkits Collection →
BEST FOR MULTIPLE ISO STANDARDS

ISO PowerPack Bundle

All 8 ISO Toolkits in One Power Pack

Designed for teams, organizations, and consultants managing multiple ISO implementations across projects and clients.

✔ Unlimited internal and client use
✔ Deliver ISO services from day one
✔ Impress clients and auditors
✔ Skip months of document creation
✔ Grow your consulting business

💡All the benefits of our ISO toolkits combined in one powerful bundle — save over $1,000 compared to buying the toolkits individually.

View ISO PowerPack →