This document gives an overview of the concepts and principles used in the documents related to information security management systems (ISMS), including ISO/IEC 27001. This document is considered to be a horizontal document as it provides an explanation of the concepts and principles that underpin information security and ISMS