top of page

27007 audit standard "on-track"

3 hours ago
1 min read

The fourth edition of ISO/IEC 27007 is on-track for publication by mid-2027.


Aside from revising the title to "Information security, cybersecurity and privacy protection — Guidelines for information security management systems auditing", and updating numerous references to the current editions of ISO/IEC 27001 and ISO 19011, the forthcoming fourth edition remains largely unchanged from the third.


It still concerns conformity or compliance "tick-n-bash" auditing, specifically, largely duplicating ISO/IEC 27006-1 (despite claiming the opposite) and missing a golden opportunity to expand the guidance to cover other valuable auditing topics in the context of ISO27k, information risk and security, privacy, safety and so forth.


Scroll down the ISO/IEC 27007 page to the Commentary section for the full list - more accurately, an extensive but still incomplete list of twenty (yes, 20) potential technology audit topics not covered by the standard.


I am disappointed but not at all surprised that the committee has taken so long to make so little progress. The project to update the standard has been constrained throughout by its design specification, defined back in 2024 (two full years after the release of the current edition of ISO/IEC 27001!):


On the upside, it has achieved what it set out to do. On the downside, it has taken two and a half further years to make very limited progress.


I despair.


CES is collaborating with ISO and IEC on this revision project, and according to the design spec CASCO was to be involved, but I wonder whether ISACA was engaged and is aware of the scope limitations?

 
 

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page