top of page
ISO27k standards
News and info on the standards


ISO/IEC 27091 AI privacy DIS
Voting has commenced on the D raft I nternational S tandard ISO/IEC 27091 on AI privacy, with national standards bodies invited to vote and comment by Feb 25th 2026. I have updated the standard's page on this website , based on a brief skim-reading of the DIS, so far. I will update that page if I find the time to study the standard properly and reconsider my opinions. In summary, although I have concerns about the scope, focus and coverage of the standard, it does offer us
2 days ago1 min read
Â


ISO/IEC 27045 big data DIS
The D raft I nternational S tandard version of this forthcoming security and privacy standard on 'big data' has been released for national bodies to vote and comment before March 2026. Supplementing ISO's 'official' page about this standard , I have outlined the structure of the standard on its detailed info page on this website. If the DIS is approved by the voting members of ISO/IEC JTC 1/SC 27 without significant comments or objections, it may be published later in 2026
5 days ago1 min read
Â


ISO/IEC 27003 revision
Patiently chiselling another work of art for ISO This month I am slaving away, diligently reviewing a C ommittee D raft of the next release of ISO/IEC 27003 , updating the 2017 second edition. ISO/IEC 27003:2017 provided 'explanation and guidance' on ISO/IEC 27001:2013. In practice, that meant mostly elaborating quite formally on the mandatory requirements from the main body of '27001. According to the editorial team, the standard revision project was supposed to take place
Dec 13 min read
Â


Infosec control attributes
ISO/IEC TS 27028 moved a step closer to publication by passing a vote at DIS stage. When released in the middle of 2026, the standard will have a new title not now mentioning ISO/IEC 27002: Guideline on using information security control attributes and a succinct scope: This document provides guidance on the use of information security control attributes. The guidance set out given in this document is generic and is intended to be applicable to all organizations, regardless
Nov 292 min read
Â


ISMS implementation & SME security guidance
ISO/IEC JTC 1/SC 27/WG 1 has two interesting new projects on the cards ... ISMS implementation First comes a proposal to develop ISMS implementation guidance, essentially rejuvenating the original ISO/IEC 27003 . When the standard's 2010 first edition was revised in 2017, the committee decided to reduce the implementation guidance, instead focusing on explaining the I nformation S ecurity M anagement S ystem requirements in ISO/IEC 27001 . At the time (and subsequently, t
Nov 274 min read
Â


Standard tensions
When drafting technical standards, there are natural tensions concerning the audience, purpose and language used. On the one hand, 'technical' implies complexities and precision in the content, with details relating to science and engineering. This generally means writing for a competent and knowledgeable professional audience, providing specific details to guide and enable them to get to grips with the subject matter. A technical standard on, say, nuts and bolts would typi
Nov 263 min read
Â


ISO/IEC 27566-2 page updated
An initial draft of this standard has been released to SC27 as the first W orking D raft, so I took the opportunity to update the info page. '27566 concerns age verification - techniques to determine the age of a website or app user, for example to prevent minors accessing adult materials. Part 2 will form a bridge linking the foundational concepts in part 1 with the analytical approaches in part 3. It will advise on how to ascertain the age verification objectives, parame
Nov 141 min read
Â


SoA risks
Before the sun came up this morning, fueled by strong coffee and prompted by yet another lame social media thread about this, I've written a new FAQ concerning disclosure of the S tatement o f A pplicability. On LinkeDin, there's the usual confusing muddle of concerns and conflicting advice when someone asked whether a company can share its SoA, adding that (according to someone on Reddit last night [allegedly]) the [certification?] auditor said they "cannot share the SoA bec
Nov 101 min read
Â
bottom of page
