top of page

ISO/IEC 27007

ISO/IEC 27007:2020 — Information security, cybersecurity and privacy protection — Guidelines for information security management systems auditing 

(third edition)

Abstract

ISO/IEC 27007 "provides guidance on managing an information security management system (ISMS) audit programme, on conducting audits, and on the competence of ISMS auditors, in addition to the guidance contained in ISO 19011. [ISO/IEC 27007] is applicable to those needing to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme.”


[Source: ISO/IEC 27007:2020]

Introduction

ISO/IEC 27007 provides guidance for internal auditors, external/third party auditors (e.g. those performing supplier security assessments) and others auditing ISMSs against ISO/IEC 27001 i.e. auditing the Management System for conformity with the standard.


For Certification Bodies' conformity assessors, it supplements or complements the mandatory accreditation requirements specified formally in ISO/IEC 27006-1 with additional discretionary advice.


The standard covers the process of ISMS-specific conformity assessment or auditing, emphasising the 'management system' elements:

  • Managing the ISMS audit programme (determining what conformity elements to audit, when and how; assigning appropriate auditors; managing audit risks; maintaining audit records; continuous process improvement);

  • Performing an ISMS MS audit (audit process - planning, conduct, key audit activities including fieldwork, analysis, reporting and follow-ups);

  • Managing ISMS auditors (competencies, skills, attributes and evaluation).

Scope

"[ISO/IEC 27007] provides guidance on managing an information security management system (ISMS) audit programme, on conducting audits, and on the competence of ISMS auditors, in addition to the guidance contained in ISO 19011.


[ISO/IEC 27007] is applicable to those needing to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme."

[Source: ISO/IEC 27007:2020]

Structure

Main clauses:

  • 4: Principles of auditing

  • 5: Managing an audit programme

  • 6: Conducting an audit

  • 7: Competence and evaluation of auditors

  • Annex A: Guidance for ISMS auditing practice - includes advice re the documentation required by ISO/IEC 27001:2013 such as the Statement of Applicability.


The main body of the standard mostly cites clauses from ISO 19011. It provides limited advice for conformity auditing in the ISMS context, with a few not-terribly-helpful explanatory comments (e.g. audits are likely to involve sensitive proprietary or personal information, hence auditors may need to be security-cleared to the appropriate level before auditing, and to secure audit evidence appropriately).


However the more valuable annex describes specific audit tests concerning an organisation’s conformity with the requirements of [the 2013 edition of] ISO/IEC 27001.

Status

The first edition was published in 2011.


The second edition was published in 2017.


The current third edition was published in 2020.


A fourth edition is in the works, belatedly reflecting ISO/IEC 27001:2022 and now ISO 19011:2026 which, for instance, provides guidance on remote auditing of virtual locations such as geographically-dispersed data centres providing cloud services. CEN, the European Committee for Standardization, is collaborating with ISO and IEC on this one. The fourth edition is at Draft International Standard stage, on track for publication by mid-2027. Hopefully the terminology and concepts will align more closely with 27000, 27001, 27003 and 27005 without implying, suggesting or stating additional requirements beyond those formally stated in 27001.  

Commentary

As with ISO/IEC 27006-1, this standard primarily concerns conformity or compliance auditing, a particular form of auditing with a specific goal: to determine whether the audited organisation’s ISMS conforms with (i.e. fulfills all the mandatory requirements specified formally by) ISO/IEC 27001. Such audits are primarily performed for certification purposes so - confusingly - the standard defers to ISO/IEC 27006.


Other types of audits (not addressed by 27007) have different assurance goals. Please don’t make the mistake of assuming that all auditors are so-called “tick-and-bash” compliance/conformity auditors, or that all audits are compliance/conformity audits. Specifically in relation to information risk and security management, competent technology auditors might for instance:

  • Evaluate the organisation’s strategies and policies relating to information and privacy risk management, incident management, fraud etc. for aspects such as strategic fit, currency, relevance, readability, coverage, suitability and quality (fitness for purpose);

  • Audit workers’ conformity with organisational policies, procedures, directives, guidelines, employment contracts etc., in the general area of information risk, information security and privacy;

  • Delve into the root causes of ongoing issues and repetitive or persistent incidents amd issues, including near-misses and lesser events;

  • Examine the governance arrangements in this area e.g. organisational structure, internal and external reporting relationships, information flows within and between management layers, accountabilities, roles and responsibilities, recruitment practices, competences ...

  • Audit the organisation’s compliance/conformity with other relevant obligations and expectations, apart from ISO/IEC 27001 e.g. privacy and data protection, intellectual property protection, health and safety, and employment laws and regulations; fire codes and building standards; technical security standards and protocols; supplier, partner and customer agreements and contracts; industry guidelines; ethical codes ... including the associated arrangements such as enforcement actions, and how the organisation stays up-to-date with changes in the requirements and expectations;

  • Audit the effectiveness and efficiency of the ISMS, including aspects such as the net value (benefits less costs) it generates for the business, aiming to substantiate and release any unrealised potential;

  • Examine ‘assurance’, ‘integrity’, ‘confidentiality’, ‘availability’, ‘risk’, ‘information risk management’, ‘compliance’, ‘privacy’ etc. in the broad, deliberately interpreting such words and phrases very widely to take in related aspects that are not usually considered in any depth;

  • Review improvements made and explore further opportunities to improve the ISMS;

  • Examine the organisation’s potential and actual exploitation of other standards, methods and frameworks relating to information risk and security management;

  • Survey, compare and contrast various stakeholders’ opinions, comments and suggestions on the ISMS, teasing-out and addressing deeper, longstanding concerns and points of common interest that might otherwise remain chronic;

  • Follow-up on previous ISMS audits, management reviews, penetration tests, security assessments, post incident reports etc., delving deeper into areas of concern, perhaps extending the scope and picking-up on recurrent, widespread and politically-sensitive (hidden or suppressed) issues;

  • Examining assurance management e.g. the manner in which various audits or assessments are scoped, approved, resourced, conducted, reported, actioned and closed off, treating ISMS or technology audits as important examples;

  • Explore the business, strategic, management, operational and supply chain aspects of business continuity and resilience, including the IT and OT aspects such as dependence on single points of failure, legacy systems;

  • Look into the integration and interoperability of various management systems such as the ISMS, PIMS, AIMS and others;

  • Audit plans, preparations and progress for the impending transition to quantum-safe cryptography including architectural and business aspects such as crypto-agility; 

  • Examine the positive and negative impacts of AI on the organisation, whether realised, planned or potential, reviewing aspects such as the business and technical objectives, systems, processes, people, supply chain, risk and security implications, resilience, ethics, safety, capabilties, costs ...

  • Audit the organisation’s information management as a whole, such as the integration of risk and security aspects with other business imperatives, and the proactive exploitation of information despite various risks;

  • Benchmark the ISMS against comparable organisations or business units, or against other operational management systems e.g. quality assurance, environmental protection;

  • Measure and comment on the organisation’s maturity in this general area;

  • Review the organisation’s use of security metrics, reports and other management information.


Despite being an incomplete list, there are clearly plenty of creative possibilities for auditing in the context of an ISMS. There's more to it than conformity-assessment tick-n-bash.


IMNSHO one of the best things about auditing is the chance to do something different for a change, looking at things with fresh eyes from different angles. Exploit the auditors’ independence, competence, experience, skills, focus, information access, rigorous methods, trustworthiness, access to senior management etc. to delve into aspects that are rarely if ever addressed as part of routine management and operations - potentially including those awkward politically-charged issues that are studiously avoided, and longstanding problems that seem destined to remain, forever.  Competent auditors have a knack of finding rut-escape routes.


Some pessimists see audits as information threats to be avoided or minimised: speaking as a former (lapsed? Reformed!) IT auditor and optimist (realist!), I see audits as valuable business opportunities to be exploited to the max. Make the best of them. Milk the value. 


Less tick-n-bash, more tick-n-cash please!

This page last updated:

24 September 2026

​

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page