top of page
Security


ISO27k SME infosec guide
ISO/IEC JTC 1/SC 27/WG 1 is making progress on a proposed new ISO27k information security standard for Small to Mid-sized Enterprises with up to ~250 people. An initial rough draft will be fleshed-out over the coming years if the project is approved by the committee in its meeting at the end of this month. The draft's 39 SME information security controls are drawn from/basd loosely on ISO/IEC 27002 controls: Half the controls are classified as "Initial baseline", suggested a
4 hours ago2 min read


ISO/IEC 27017 (cloud security) updated
After more than a decade, the first edition of ISO/IEC 27017 and ITU-T recommendation X.1631 has been updated. The standard advises both Cloud Service Customers and Cloud Service Providers, providing complementary security guidance side-by-side in tables. Clauses 5 through 8 in the new second edition adopt the structure of ISO/IEC 27002:2022: Clause 4 sets the scene with general guidance and concepts; Clause 5 covers organizational controls for cloud services; Clause 6 covers
Aug 191 min read


Generic infosec controls
ISO/IEC JTC 1/SC 27 is in the early stages of updating ISO/IEC 27002:2022 - the generic set of information security controls generally worth considering, whether as part of a '27001 Information Security Management System or not. Rather than leaping straight into the usual process of inviting then discussing and addressing comments and proposed changes, the revision project's editorial team is taking a different route this time around: the committee intends to decide what cha
Jul 195 min read


Adversaries as 'interested parties'
ISO/IEC 27000:2016 clause 4.4 "Why an ISMS is important" explained the purpose of information security and an ISMS in about a page of 7 paragraphs. In ISO/IEC 27000:2026, that clause became 4.1.7 "Importance of an ISMS" and was condensed to half a page with 3 paragraphs. It's more than just a tightening-up of the wording, though, including this new text: "Interested parties can include not only the organization’s customers, suppliers, business partners, employees, shareholde
Jul 163 min read


AI security standard 27090
Earlier today I blogged about the tedium and risks of ISO's slow processes, both consequences of the effort needed to align all those involved in standardisation and produce worthwhile, generally-acceptable standards. Here's another topical example. ISO/IEC 27090 "Cybersecurity — Artificial Intelligence — Guidance for addressing security threats and compromises to artificial intelligence systems" is at FDIS stage and will hopefully emerge from the sausage machine "soon-as", m
Jun 62 min read


27000 & 27017 updates "soon-as"
Updates to both ISO/IEC 27000 and ISO/IEC 27017 have passed their votes at FDIS stage. 27000 (the overview and introduction to the ISO27k standards) received just a few minor comments and should be released very soon (which means within months, in ISO-land). 27017 (cloud security) received about 10 pages of comments - mostly minor grammatical corrections though, so it too remains on-track for release soon (hopefully this year). They should be published "soon-as". I often moa
Jun 62 min read


Portuguese toolkit materials
Graças a Filipe Nicacio, agora oferecemos traduções para português brasileiro de alguns materiais do ISO27k Toolkit. Pedimos desculpas por eventuais erros: não consigo revisá-los, pois a única palavra em português que sei é "Obrigado!"... e meu sotaque é péssimo! [Courtesy of Filipe Nicacio, we now offer Brazilian Portuguese translations of some of the ISO27k Toolkit materials. Sorry about any mistakes: I can't really check them since about the only word of Portuguese I know
Apr 221 min read


Losing faith in ISO27k
ISO/IEC 27002 - a generic catalogue of commonplace information security controls - expands substantially on Annex A of ISO/IEC 27001. Each of the 93 single-sentence control statements in Annex A merits about a page of more detailed explanation and guidance in '27002 ... but those details mean more work for ISO/IEC JTC 1/SC27 to maintain the standard. The committee is forever chasing after changes in the field such as the meteoric rise of generative AI since the release of Cha
Apr 164 min read


AI security standard at FDIS
Having now reached F inal D raft I nternational S tandard stage, ISO/IEC 27090 " Guidance for addressing security threats and compromises to artificial intelligence systems " is on-track for publication later this year, hopefully. This is a timely standard, giving the explosion of AI-with-everything at the moment. Hopefully it will prompt smart (and not-so-smart!) organisations to think carefully about the information risks associated with their use of AI, prioritising the
Feb 201 min read


12 << 5555
In part, the current (fifth, 2018) edition of ISO/IEC 27000 defines key terms of art used throughout the ISO27k standards . The standard is available as a legitimate free download from ISO . If you haven't already seen it, go ahead - download the standard for a good look at these 77 terms defined in clause 3: access control attack audit audit scope authentication authenticity availability base measure competence confidentiality conformity consequence continual improvement c
Feb 162 min read


ISO/IEC TS 27103 published
Cover page ISO/IEC TS 27103:2026 "Cybersecurity - Guidance on using ISO and IEC standards in a cybersecurity framework" is, essentially, a mapping of NIST's C yber S ecurity F ramework to ISO27k and other standards. The Technical Specification belatedly updates references to various clauses in the 2022 editions of ISO/IEC 27001 and 27002 from 2018's T echnical R eport. Read more about the standard here on this site and at ISO.org
Feb 101 min read


Two new ISO27k projects: ISMS guidance for the neglected mediums and the SME dilemma
No, not that kind of 'medium'! Two new ISO/IEC JTC 1/SC 27/WG 1 standards projects are under way, raising fundamental questions about how we standardise and promote information security. 1. Practical ISMS implementation guidance First, we are defining the scope and plan for a second part to ISO/IEC 27003 (possibly a distinct standard or some other format). This project aims to offer ISMS implementation advice for small, medium and large organizations, with a specific emphas
Jan 232 min read


Cyber-insurance standard update
I've received the first W orking D raft for the revision of ISO/IEC 27102 :2019 - "Information security management - Guidelines for cyber-insurance ". With a new title already approved ("Information security, cybersecurity and privacy protection — Guidelines for applying ISO/IEC 27001 and related standards in support of cyber insurance ") and a revised scope, the committee intends to refocus the second edition more explicitly on the I nformation S ecurity M anagement S ystem
Jan 172 min read


That risky Annex A
Having seen yet another comment on social media this morning along the lines of "I'm petrified that the certification auditor will raise a nonconformity if we don't adopt specific Annex A controls", I've added an ISO27k FAQ under the assurance section . This is one of the most frequent of F requently A sked Q uestions, a frustratingly persistent concern relating to the natural anxieties about being audited. I've been audited. I've been an auditor. Audits are challenging,
Jan 32 min read


Stakeholding adversaries
I'm intrigued by the notion of 'adversaries' being classed and treated as 'stakeholders' for risk management purposes. Adversaries' interests, concerns, requirements and expectations are (on the whole) diametrically opposed to the organisation's and its more conventional stakeholders. However, as with all stakeholders ( e.g . owners, workers, partners, suppliers, customers, authorities, communities, society ...), they are willing to invest in achieving the outcomes they desir
Dec 23, 20252 min read


ISO 27799 updated - health infosec controls
ISO/TC 215 has updated ISO 27799 to reflect ISO/IEC 27002:2022 , omitting the previous edition's content re ISO/IEC 27001 . The standard now concentrates on the implementation of organisational, people, physical and technological controls within the healthcare industry.
Dec 19, 20251 min read


Age verification standards
ISO/IEC 27566-1:2025 "Information security, cybersecurity and privacy protection — Age assurance systems — Part 1: Framework " has been published. This is the start of a multi-part standard concerning the tricky process of verifying someone's age to an appropriate level of assurance, without unnecessarily invading or compromising their privacy rights. As usual for a 'part 1', it provides a general introduction and conceptual basis for the framework that the remaining parts wi
Dec 17, 20252 min read


ISO/IEC 27028 Control attributes DIS
An updated D raft I nternational S tandard ISO/IEC 27028 has been released to ISO/IEC JTC 1/SC 27 for voting by early February 2026. I have been expecting a 'Technical Specification' rather than full International Standard but maybe I missed the memo. Not to worry. The DIS is in good shape. So far I spotted just a few minor grammatical issues and concerns about terminology (risk tolerance denotes a different concept to risk appetite, - these are not synonyms; likewise for 'co
Dec 16, 20251 min read


Prosthetic privacy
A new SC27 project has been approved, developing an ISO27k standard on privacy for the B rain- C omputer I nterface, part of meditech or healthtech you could say. Consider the privacy implications of these vaguely-conceivable futuristic or other-worldly BCI applications: Brain implants picking-up neurological signals to control prosthetic limbs or weapons, ideally providing 'force feedback' for proportional control, dexterity and accuracy. Remote control/direction of animal
Dec 16, 20252 min read


ISO/IEC 27091 AI privacy DIS
Voting has commenced on the D raft I nternational S tandard ISO/IEC 27091 on AI privacy, with national standards bodies invited to vote and comment by Feb 25th 2026. I have updated the standard's page on this website , based on a brief skim-reading of the DIS, so far. I will update that page if I find the time to study the standard properly and reconsider my opinions. In summary, although I have concerns about the scope, focus and coverage of the standard, it does offer us
Dec 6, 20251 min read
bottom of page
