Search Results
125 results found with an empty search
- ISO/IEC TS 27110 | ISO27001security
Back Up Next ISO/IEC TS 27110 ISO/IEC TS 27110:2021 — Information security, cybersecurity and privacy protection — Cybersecurity framework development guidelines (first edition) Up Abstract “[ISO/IEC TS 27110] specifies guidelines for developing a cybersecurity framework. It is applicable to cybersecurity framework creators regardless of their organisations' type, size or nature.” [Source: ISO/IEC TS 27110:2021)] Introduction This T echnical S pecification offers guidance for those within organisations who are creating cybersecurity frameworks, defined as “basic sets of concepts used to organize and communicate cybersecurity activities” . Scope The standard “specifies guidelines for developing a cybersecurity framework.” Structure Main clauses: 5: Overview 6: Concepts 7: Creating a cybersecurity framework Annex A: Considerations in the creation of a cybersecurity framework - outlines some inputs, activities and outputs for each of the identify, protect, detect, respond and recover stages Annex B: considerations in the integration of a cybersecurity framework - concerns its 'integration into practice' a.k.a. implementation Status The current first edition was published as a T echnical S pecification in 2021 and confirmed unchanged in 2024. Commentary The intended audience and purpose of this standard is hard to fathom. Who is it for, and what is a “cybersecurity framework” anyway? Whose ‘burden’ is it seeking to lighten, and what is the nature of their burden? According to the introduction, “business groups, government agencies, and other organisations produce documents and tools called cybersecurity frameworks to help organize and communicate cybersecurity activities of organisations” . My toolbox contains no “cybersecurity frameworks” so I guess this standard is not aimed at me; The standard makes no attempt to explain what it means by ‘cybersecurity’. This is yet another ISO27k ‘cybersecurity’ project that studiously avoids defining the term, using woolly language to confuse instead of clarify. So much for international standards pushing back the frontiers; The distinction between “creators” and “implementors” of “cybersecurity frameworks” implies a conventional waterfall approach i.e. someone first identifies requirements, designs and develops a solution (the “framework”) which someone else then puts into operation. There is no hint presently that the process might be iterative, or that both phases would need to be governed and managed appropriately. However, I’m guessing here since the standard does not elaborate: it simply states that framework creators are its intended audience; The ‘concepts’ that (according to the standard) “should be included in a cybersecurity framework” simply reflect the usual pre-, para- and post-incident stages, another simplistic linear timeline. This is hardly rocket surgery. However, the standard makes no attempt to justify why these specific ‘concepts’ ‘should’ be ‘included’, and completely ignores the possibility of other potential ‘concepts’ or framework structures (such as ISO/IEC 27001 to name but one of several); The examples listed in Annex C suggest a “cybersecurity framework” might be a strategic approach for dealing with (presumably IT and Internet-related information) risks to critical national infrastructures, implying therefore that the ‘cybersecurity framework creators’ would be government officials. But I’m guessing again, pecking between the lines like a hungry chicken for tiny crumbs of sense. The relationship between a “cybersecurity framework” and a conventional ISMS remains unclear at this point. Those “documents and tools” sound to me suspiciously like the embodiment of a management system, despite the draft standard stating categorically “This document is not intended to supersede or replace the requirements of an ISMS given in 27001” [sic] . To my cynical, perhaps jaundiced eye, this looks suspiciously like an attempt to align ISO27k with - or perhaps amend ISO27k to embody - NIST’s C yber S ecurity F ramework specifically. Organisations that prefer the CSF are of course free to adopt it, so why change ISO27k, especially while “cybersecurity” remains a solid-gold buzzword that consistently defies definition? Oh I despair! Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27553-1 | ISO27001security
Back Up Next ISO/IEC 27553-1 ISO/IEC 27553-1:2022 — Information security, cybersecurity and privacy protection — Security and privacy requirements for authentication using biometrics on mobile devices — Part 1: local modes (first edition) Up Abstract ISO/IEC 27553 part 1 "provides high-level security and privacy requirements and recommendations for authentication using biometrics on mobile devices, including security and privacy requirements and recommendations for functional components and for communication. [The standard] is applicable to the cases that the biometric data and derived biometric data do not leave the device, i.e. local modes.” [Source: ISO/IEC 27553-1:2022 ] Introduction This multi-part standard provides high-level requirements for biometric authentication on mobile devices, including functional components and communications. Biometrics are increasingly used for user authentication on mobile devices. They are easier to use and harder to steal or fake than conventional passwords and tokens. However, proliferating devices and approaches are fragmenting the market, hence standardization offers advantages for users and manufacturers. Scope Biometric authentication on mobile devices. Part 1 applies where the user of a mobile ICT device such as a smartphone or tablet PC biometrically authenticates directly to the device such as when logging on to unlock the device, access stored data and run mobile apps. Although the outcome of biometric authentication may be used elsewhere (e.g . in cloud or corporate server apps), this standard specifically concerns risks to and protection of the biometrics on the device itself (e.g . fingerprints). The standard references ISO/IEC 24745:2022 “Biometric information protection”. Structure Main clauses: 5: Security challenges 6: System description 7: Information assets 8: Threat analysis 9 :Security requirements and recommendations 10: Privacy considerations Annex A: Implementation example Annex B: Security issues related to communication between agents and servers for authentication using biometric on mobile devices Annex C: An example of authentication assurance and assurance levels Status The current first edition was published in 2022 . Commentary As a generic standard, part 1 addresses commonplace information risks that typically arise in relation to biometrics on mobiles. In practice, we should manage (identify, evaluate, treat and monitor) the actual information and privacy risks in real-world situations, including any that are not explicitly identified and accurately described in this standard. That is context-dependent - for instance, the information risks relating to my biometrics on my cellphone are broadly similar but not entirely the same as, say, the king’s or yours, not least because the impacts of any incidents would probably be materially different. Aside from the security and privacy implications arising, there may also be different assurance requirements relating to biometric authentication. The consequences of someone accessing my smartphone without authorisation are rather different in the case of the president's. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27033-3 | ISO27001security
Back Up Next ISO/IEC 27033-3 ISO/IEC 27033-3:2010 Information technology — Security techniques — Network security — Part 3: Reference networking scenarios — threats, design techniques and control issues (first edition) Up Abstract ISO/IEC 27033 part 3 “describes the threats, design techniques and control issues associated with reference network scenarios. For each scenario, it provides detailed guidance on the security threats and the security design techniques and controls required to mitigate the associated risks. Where relevant, it includes references to ISO/IEC 27033-4 to ISO/IEC 27033-6 to avoid duplicating the content of those documents. The information in ISO/IEC 27033-3:2010 is for use when reviewing technical security architecture/design options and when selecting and documenting the preferred technical security architecture/design and related security controls, in accordance with ISO/IEC 27033-2. The particular information selected (together with information selected from ISO/IEC 27033-4 to ISO/IEC 27033-6) will depend on the characteristics of the network environment under review, i.e. the particular network scenario(s) and ‘technology’ topic(s) concerned. Overall, ISO/IEC 27033-3:2010 will aid considerably the comprehensive definition and implementation of security for any organization's network environment.” [Source: ISO/IEC 27033-3:2010] Introduction Using a set of 'reference scenarios' (worked examples), part 3 demonstrates how to identify, evaluate and treat typical information risks in the networking security context. Scope Part 3 intended to“define the specific risks, design techniques and control issues associated with typical network scenarios” [Source: ISO/IEC 27033-1] . Structure Main clauses: 7: Internet access services for employees 8: Business to business services 9: Business to customer services 10: Enhanced collaboration services 11: Network segmentation 12: Networking support for home and small business offices 13: Mobile communication 14: Networking support for travelling users 15: Outsourced services Annex A: Example Internet use policy Annex B: Catalogue of threats Status The current first edition of part 3 was published long, long ago in 2010 ... and confirmed unchanged in 2018. Commentary This standard: Discusses threats, specifically, rather than all the elements of risk. Refers to other parts of ISO/IEC 27033 for more specific guidance. This 2010 standard is way out of date (as it was back in 2018 when it was confirmed), despite ironically noting "the evolving nature of technology". There is no mention of 'cloud', for instance. Not one. None. Zilch. Zero. Nor 'zero trust', for that matter, nor '*aaS'. 'AES' is in there, however, so it's not totally prehistoric. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27021 | ISO27001security
Back Up Next ISO/IEC 27021 ISO/IEC 27021:2017 (amended ) — Information technology — Security techniques — Competence requirements for information security management systems professionals (first edition) Up Abstract “ISO/IEC 27021:2017 specifies the requirements of competence for ISMS professionals leading or involved in establishing, implementing, maintaining and continually improving one or more information security management system processes that conforms to ISO/IEC 27001.” [Source: ISO/IEC 27021:2017] Introduction To help stabilise and standardise the global market for training and certifying professionals for ISO27k implementation and audit work, this standard lays out the competence expected of ISMS professionals. Scope The standard concerns the competences (meaning the combination of knowledge and skills) required or expected of professionals managing an ISMS in accordance with ISO/IEC 27001 , ISO/IEC 27002 , ISO/IEC 27005 and ISO/IEC 27007 . Note : the standard does not specify a qualification scheme as such, but in effect serves as a reference for the organisations that offer such schemes. Note : the standard does not cover auditor competence. Structure Main clauses: 4: Concept and structure 5: Business management competence for ISMS professionals 6: Information security competence for ISMS professionals Annex A: Including knowledge for ISMS professionals as parr of a body of knowledge The standard starts by explaining that an ISMS is just one form of Management System, requiring a combination of competences in general business management (e.g. leadership and communication, planning and budgeting) plus information security/ISMS management (e.g. scoping the ISMS). The competences roughly mirror the main body clauses of ISO/IEC 27001 , except that most of the general management competences are not directly related to specific clauses. Each competence is described quite succinctly in four ways: Relevant ISO/IEC 27001 clause (where applicable) Intended outcome: what this part of the role entails and is expected to achieve Knowledge required: things the ISMS professional should know about Skills required: things the ISMS professional should be able to do Status The first edition was published in 2017 . Additional references to ISO/IEC 27001 clauses were added to plug gaps in the competencies table through an amendment in 2021: ISO/IEC 27021:2017/Amd1:2021 Information technology - Security techniques - Competence requirements for information security management systems professionals - Amendment 1: Addition of ISO/IEC 27001:2013 clauses or subclauses to competence requirements . Commentary Although the title of this standard includes the reserved word ‘requirements’, that should not be taken to imply this is a certifiable standard. The four standards listed in the scope section above may be the ‘core standards’ but they represent just a fraction of the growing ISO27k suite . It could be argued that several others are nearly as important - ISO/IEC 27003 and ISO/IEC 27004 for examples - which begs questions about the breadth and depth of knowledge and competencies truly expected of information security managers. Another aspect is that (ISO27k notwithstanding) information security management is materially different in different types/sizes of organisation, so perhaps there is a need for different levels or tiers of qualification (or practitioner maturity, you could say), from entry-level basics up to subject matter experts? A tiered scheme would also encourage career development and lifelong learning. Since the standard is intended to guide those developing courses and qualifications, it might make sense to incorporate or build the standard around a matrix listing the skills and competencies on one axis and the levels or tiers on another, indicating in the body of the matrix which items people at that level/tier are expected to know about and be competent to perform. The idea of a tiered scheme was agreed in principle by the project team, with e-CF and e-QF schemes (whatever they are!) being mentioned during drafting: maybe this suggestion will be revisited when the standard is next revised. The standard incorporates the idea of a B ody o f K nowledge defined in the standard to cover the core aspects of governing and managing an ISMS, but extendable by organisations to address their specific additional requirements in this area. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27033-4 | ISO27001security
Back Up Next ISO/IEC 27033-4 ISO/IEC 27033-4:2014 Information technology — Security techniques — Network security — Part 4: Securing communications between networks using security gateways (first edition) Up Abstract ISO/IEC 27033 part 4 “gives guidance for securing communications between networks using security gateways (firewall, application firewall, Intrusion Protection System, etc.) in accordance with a documented information security policy of the security gateways, including: identifying and analysing network security threats associated with security gateways; defining network security requirements for security gateways based on threat analysis; using techniques for design and implementation to address the threats and control aspects associated with typical network scenarios; and addressing issues associated with implementing, operating, monitoring and reviewing network security gateway controls.” [Source: ISO/IEC 27033-4:2014] Introduction Part 4 gives an overview of security gateways , describing different architectures. Scope Guidance on securing communications between networks through gateways, firewalls, application firewalls, Intrusion Protection System [sic ] etc . in accordance with a policy. Includes identifying and analysing network security threats, defining security control requirements, and designing, implementing, operating, monitoring and reviewing the controls. Structure Main clauses: 6: Overview 7: Security threats 8: Security requirements 9: Security controls 10: Design techniques 11: Guidelines for product selection Status ISO/IEC 27033-4 revised and replaced ISO/IEC 18028-3 . The current first edition of part 4 was published in 2014 and confirmed unchanged in 2019. It is slightly more up to date than other parts of ISO/IDC 27033 in that it mentions 'cloud', twice, and even VoIP. Gosh. Denial-Of-Service attacks on corporate networks were evidently a big concern back in 2014, but ransomware was yet to make its big entrance stage right. Commentary The standard outlines how security gateways (a.k.a. firewalls) analyse and control network traffic through: Packet filtering; Stateful packet inspection; Application proxy (application firewalls); N etwork A ddress T ranslation; Content analysis and filtering. It guides the selection and configuration of security gateways, choosing the right type of architecture for a security gateway which best meets the security requirements of an organisation. It refers to various kinds of firewall as examples of security gateways. [Firewall is a commonplace term of art that is curiously absent from ISO/IEC 27000 and ISO/IEC 27002 , neither is it defined explicitly in this standard. I wonder if some ancient ISO standard had already 'taken' the term to describe a physical barrier impeding the spread of fire and smoke e.g. from the engine into the passenger compartments of a car?]. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27018 | ISO27001security
Back Up Next ISO/IEC 27018 ISO/IEC 27018:2025 — Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors (third edition) Up Abstract ISO/IEC 27018 "establishes commonly accepted control objectives, controls and guidelines for implementing measures to protect personally identifiable information (PII) in line with the privacy principles in ISO/IEC 29100 for the public cloud computing environment. In particular, [ISO/IEC 27018] specifies guidelines based on ISO/IEC 27002:2022, taking into consideration the regulatory requirements for the protection of PII which can be applicable within the context of the information security risk environment(s) of a provider of public cloud services ... The guidelines in [ISO/IEC 27018] can also be relevant to organizations acting as PII controllers.” [Source: ISO/IEC 27018:2025] Introduction This standard provides guidance aimed at ensuring that cloud service providers (such as Amazon and Google) offer suitable information security controls to protect the privacy of their customers’ clients by securing P ersonally I dentifiable I nformation entrusted to them. See also ISO/IEC 27017 covering the wider information security angles of cloud computing, aside from privacy. The standard development project had widespread support from national standards bodies plus the C loud S ecurity A lliance . Scope ISO/IEC 27018 intends to be “a reference for selecting PII protection controls within the process of implementing a cloud computing information security management system based on ISO/IEC 27001 , or as a guidance document for organisations for implementing commonly accepted PII protection controls” . The standard is primarily concerned with public-cloud computing service providers processing PII . “A public cloud service provider is a 'PII processor' when it processes PII for and according to the instructions of a cloud service customer” [according to the DIS version]. It does not officially cover PII principals (i.e. individuals processing their own PII in the cloud, for example using Google Drive) or PII controllers (i.e. cloud service customers processing PII of their clients/customers/employees and others in the cloud), although they clearly share many concerns and have an interest in the cloud service provider’s privacy controls. The standard interprets rather than duplicates ISO/IEC 27002 in the context of securing personal data processed in the cloud. An annex extends 27002, for example advising cloud service providers to advise their customers if they use sub-contractors. ISO/IEC 27000 , ISO/IEC 27001 and ISO/IEC 27002 are cited as ‘normative’ (i.e. essential) standards, along with ISO/IEC 17788:2014 “Cloud computing - overview and vocabulary” (withdrawn - replaced by ISO/IEC 22123-1:2023 , a legitimate free download from ISO) and ISO/IEC 29100 “Privacy framework” (another free download!). Structure Main clauses: 4: Overview 5: Organizational controls 6: People controls 7: Physical controls 8: Technological controls Annex A: Public cloud PII processor extended control set for PII protection Annex B: Correspondence between this document and the first edition ISO/IEC 27018:2019 Status The first edition was published in 2014 . The second edition (a minor revision) was published in 2019 . The current third edition was published in 2025 , having been updated to reflect ISO/IEC 27002:2022 and offering an ‘extended control set’ aligned with ISO/IEC 29100:2024 Commentary The standard builds on ISO/IEC 27002 , expanding on its generic advice in a few areas, and referring to the OECD privacy principles that are enshrined in several privacy laws and regulations around the globe. In most sections, it simply says: “The objectives specified in, and the contents of, clause [whatever] of ISO/IEC 27002 apply.” The expansions or additions are straightforward - no surprises here. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27039 | ISO27001security
Back Up Next ISO/IEC 27039 ISO/IEC 27039:2015 — Information technology — Security techniques — Selection, deployment and operations of intrusion detection and prevention systems (IDPS) (first edition) Up Abstract “ISO/IEC 27039:2015 provides guidelines to assist organisations in preparing to deploy intrusion detection and prevention systems (IDPS). In particular, it addresses the selection, deployment, and operations of IDPS. It also provides background information from which these guidelines are derived.” [Source: ISO/IEC 27039:2015] Introduction I ntrusion D etection S ystems are largely automated systems for identifying attacks on and intrusions into a network or system by hackers and raising the alarm. I ntrusion P revention S ystems take the automation a step further by automatically responding to certain types of identified attack, for example by closing off specific network ports through a firewall to block identified hacker traffic. IDPS refers to either type. Scope The scope states “This International Standard provides guidelines to assist organisations in preparing to deploy Intrusion Detection Prevention System (IDPS). In particular, it addresses the selection, deployment and operations of IDPS. It also provides background information from which these guidelines are derived.” Well designed, deployed, configured, managed and operated IDPS are valuable in several respects, for example: Automation leverages scarce security engineers who would otherwise have to monitor, analyse and respond to network security incidents as best they could; Automation tends to speed-up identification and response to attacks, particularly common types of attack that can be identified unambiguously through unique attack signatures; They give additional assurance to management that security issues on the networks and networked systems are being identified and mitigated. The standard is, in effect, an ISPS implementation guide and advisory. Structure Main clauses: 5: Selection - of various types of IDPS, complementary tools etc . to consider (in some detail, expanded still further in the annex) 6: Deployment - of IDPS 7: Operations - of IDPS Annex A: Intrusion Detection and Prevention System (IDPS): framework and issues to be considered Status The current first edition was published in 2015 , “revising and canceling” (i.e. replacing) ISO/IEC 18043:2006. A technical corrigendum in 2016 corrected the title of the published standard, introducing “and prevention” that somehow got lost. The first edition was confirmed unchanged in 2020. It was due for periodic review in 2025 ... Commentary I had hoped the standard would mention, in addition to the network security risks that they are meant to address, various information risks and issues associated with or introduced by the IDPS themselves, such as: They are technologically advanced and complex controls, making them difficult to configure, deploy and use effectively. Hence there is a risk that they may be incorrectly configured, deployed or used in practice, with various consequences on the organisation and other systems. Furthermore, they probably introduce additional technical security vulnerabilities into the very networks and/or systems they are supposed to protect; They may adversely affect network traffic, restricting legitimate traffic and hence normal use of the network and systems, as well as hacking traffic; They are not 100% capable, meaning that certain types or modes of attack (particularly novel ones) may not be reliably identified and hence blocked, potentially creating a false sense of security (inappropriate assurance); They can only detect and react to available information, making them blind and deaf to attacks that bypass the networks and systems being monitored (including, for examples, social engineering and physical intrusion attacks); They usually require network bandwidth, processing and storage capacity for their own operations and record-keeping, and require hooks into the networks and systems being monitored and/or controlled, impinging upon normal use; They are complicated to configure, manage, monitor and maintain for best effect, requiring the ongoing involvement of competent security engineers who, potentially, may be hackers; They require privileged access to network traffic, network devices and/or systems, and could potentially be misused as a vector or mechanism to compromise them. However, it does not ... Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27001 | ISO27001security
Back Up Next ISO/IEC 27001 ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements (third edition) Up Abstract ISO/IEC 27001 "specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. [It] also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization ...” [Source: ISO/IEC 27001:2022] Introduction ISO/IEC 27001:2022 (known colloquially as “ISO 27001”, “ISO27001”, “27001” or “two seven double-oh one”) formally specifies an I nformation S ecurity M anagement S ystem, a governance arrangement comprising a structured suite of organised activities with which to manage risks relating to the confidentiality, integrity and availability of information (called ‘information security risks’ in the standard). According to the ISO directives part 1 annex SL , an ISMS is a set of interrelated or interacting elements of an organisation to establish policies and objectives relating to the security of information, as well as processes to achieve those objectives. An ISMS is an overarching framework through which management identifies, evaluates and treats (addresses) the organisation’s information risks. The ISMS ensures that the security arrangements are appropriately designed and fine-tuned to keep pace with changes to the security threats, vulnerabilities and business impacts. Adaptation is important in such a dynamic field, and a key advantage of ISO27k’s flexible risk-driven approach as opposed to more prescriptive and rigid approaches such as PCI-DSS. Flexibility allows the standard to apply to all types of organisations (e.g . commercial enterprises, government agencies, non-profits, clubs) of all sizes (from micro-businesses to sprawling multinationals) in all industries (e.g . retail, banking, defence, healthcare, education and government), worldwide. Given such a huge brief, the standard is necessarily generic, specifying only the bare minimum, the core ISMS requirements common to all organisations. ISO/IEC 27001 does not formally demand specific information security controls since the controls that are required vary markedly between organisations. The information security controls from ISO/IEC 27002 are summarised in annex A of ISO/IEC 27001, rather like a menu. Organisations adopting ISO/IEC 27001 are free to choose whichever specific information security controls are applicable to their particular information risks, perhaps but not necessarily drawing on those listed in the menu and potentially supplementing or replacing them with other a la carte options (known as extended or custom control sets). The way to select "necessary" (applicable) controls is to undertake a comprehensive assessment of the organisation’s information risks within scope of the ISMS: this is one vital and mandatory part of the ISMS. Furthermore, management may elect to avoid, share or accept information risks rather than mitigate them through information security controls - a risk treatment decision within the specified risk management process. Appropriate governance arrangements and management controls are also appropriate to direct, control and oversee the ISMS: the standard gives fairly rudimentary and circumspect guidance in these areas. Scope The standard applies to any organisation that needs to protect and legitimately exploit information, systematically. 'Information' may include: Business information belonging to the organisation itself, such as its financial, HR and operating info, trade secrets, intellectual property such as trademarks, designs, patents and brands, plus workers' knowledge and experience; Business information belonging to third parties , such as commercial software and content licensed or given to the organisation for custodianship, plus public or community-owned info; and Personal information belonging to individual people such as workers or supplier/customer contacts. Structure The standard has 10 clauses plus an unnumbered introduction and an annex: Scope : it specifies generic ISMS requirements suitable for organisations of any type, size or nature, in any location. Normative references : only ISO/IEC 27000 is considered absolutely essential reading for users of ’27001. Terms and definitions : see ISO/IEC 27000 . Context of the organisation : understanding the organisational/business context, the needs and expectations of ‘interested parties’ and defining the scope of the ISMS. Section 4.4 starkly states that “The organisation shall establish, implement, maintain and continually improve” the ISMS, meaning that it must be operational, not merely designed and documented. Leadership : top management must demonstrate leadership and commitment to the ISMS, mandate policy, and assign information security roles, responsibilities and authorities. Planning : outlines the process to identify, analyse and plan to treat information risks, to clarify the objectives of information security, and to manage ISMS changes. Support : adequate, competent resources must be assigned, awareness raised, documentation prepared and controlled. Operation : more detail about assessing and treating information risks, managing changes, and documenting things (partly so that they may be audited by certification auditors: certification is optional). Performance evaluation : monitor, measure, analyse and evaluate/audit/review the information security controls, processes and management system, systematically improving things where necessary. Improvement : address the findings of audits and reviews (e.g. nonconformities and corrective actions), systematically refining the ISMS. Annex A - Information security control reference : this does little more than name the controls in ISO/IEC 27002 - one sentence summaries of 27002's one page descriptions. The annex is ‘normative’ meaning that certified organisations are required to use it to check their ISMS for completeness (according to clause 6.2), but that does not mean they are required to implement the controls: given their particular information risks, they may prefer other controls or risk treatments or the corresponding risks may be irrelevant (e.g. a totally virtual organisation with no business premises and no physical presence may determine that physical security controls are pointless). Refer to ISO/IEC 27002 for lots more detail on the security controls, including useful implementation guidance, and ISO/IEC 27005 to understand information risk management. Bibliography: points readers to related standards, plus part 1 of the ISO/IEC Directives , for more information. In addition, ISO/IEC 27000 is 'normative' and there are several references to ISO 31000 on risk management. Status The first edition, based on BS 7799 Part 2 (1999), was published in 2005 . The second edition, completely revised with substantial changes to align with other ISO management systems standards, was published in 2013 , followed by two corrigenda (corrections). The current third edition, published in 2022 , has some wording changes to the main-body clauses to reflect the revised ISO directives part 1 annex SL common structure/boilerplate for all the ISO management systems standards, plus a completely restructured and revised Annex A reflecting ISO/IEC 27002:2022 . An amendment to ISO/IEC 27001:2022 was published in 2024 , formally clarifying that, in clauses 4.1 and 4.2, the ‘relevance of climate change should be considered ’ - a timely reminder to think broadly when considering the context and purpose of the ISMS. Take a look at "Secure the planet " for clues about potential touch points between information security and climate change. Commentary Whereas ISO/IEC 27001 does not use the word ‘governance’, a ‘management system’ combines a governance structure with a number of management controls to ensure management’s strategic intent is put into effect, becoming an integral part of the organisation. In the case of an ISMS, the system enables management to direct, oversee, control and gain assurance in information risk, security, privacy and related areas. Other ISO management systems standards based on the same ISO boilerplate text presumably avoid the word ‘governance’ as well. This could be considered a systematic flaw in ISO’s management systems approach. However, companion standards such as ISO/IEC 27014 provide guidance in that area. Planning for updates to any certification standard is tricky because of the need to allow time for the accreditation and certification bodies to plan and enact their transition arrangements, although ISO deliberately and pointedly stays clear of accreditation and certification so, in theory , it should not really matter. In practice , it does, meaning a delicate and ambiguous relationship between standards and certification. An ISMS documented almost entirely in the form of thought-provoking diagrams, mindmaps or motivational videos rather than the usual boring, wordy, static documents would be novel, radical, creative, perhaps even brilliant ... if only someone was willing to give it a go ... Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27559 | ISO27001security
Back Up Next ISO/IEC 27559 ISO/IEC 27559:2022 — Information security, cybersecurity and privacy protection — Privacy-enhancing data de-identification framework (first edition) Up Abstract ISO/IEC 27559 "provides a framework for identifying and mitigating re-identification risks and risks associated with the lifecycle of de-identified data.” [Source: ISO/IEC 27559:2022] Introduction This standard proposes a ‘principles-based’ framework/structure for identifying and mitigating privacy-related risks such as re-identification of supposedly de-identified data. It advises on properly de-identifying (anonymising) personal data in order to build trust with data subjects and comply with applicable privacy laws and regulations. Scope As data analytics increasingly relies on sharing and combining data sets containing supposedly de-identified (anonymized) data, the risks of re-identification are growing more significant. This standard provides guidance on the principles involved in recognizing and mitigating those risks. It stops short of the specific technologies and their implementation. Structure Main clauses: 5: Overview 6: Context assessment - essentially, determining the general concerns and hence main requirements in this area, using analytical approaches such as threat modelling. Understanding the business situations in which personal data are shared both within and without the organisation suggests the possibility of procedural and administrative controls (such as contracts and agreements) to be applied by data custodians 7: Data assessment - understanding the data structures to identify possible ‘attacks’ (unauthorised/inappropriate attempts to obtain personal information that would compromise privacy) 8: Identifiability assessment and mitigation - understanding how personal information might be gleaned from available/accumulated data that (whether individually or as a whole) has been inadequately anonymized, and mitigating the risks (e.g. applying the de-identification techniques described in ISO/IEC 20889) to an acceptable level (not necessarily zero!) 9: De-identification governance - directing and controlling the people involved in maintaining privacy, for example by determining and assigning appropriate roles and responsibilities, defining policies and procedures, managing and mopping-up after privacy breach incidents Annex A: Example identifiers Annex B: Example threshold identifiability benchmarks Status The current first edition was published in 2022 . Commentary As our personal information is increasingly obtained and shared both within and among organisations, this standard has a valuable role in setting the ground rules. It specifies how to do so without unnecessarily compromising the privacy of the individuals concerned, or exposing personal data to compromise by various means (e.g. data aggregation and inference attacks). As such, it facilitates the process by increasing the level of trust between providers and acquirers of personal information, supporting privacy arrangements in general. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27046 | ISO27001security
Back Up Next ISO/IEC 27046 ISO/IEC 27046 — Information technology — Big data security and privacy — Implementation guidelines [DRAFT] Up Abstract ISO/IEC 27046 "aims to analyze key challenges and risks of big data security and privacy, and propose guidelines for implementation of big data security and privacy in aspects of big data resources, and organizing, distributing, computing and destroying big data.” [Source: ISO/IEC JTC 1/SC 27 Committee Doc 11, May 2025] Introduction This standard was intended to help organisations implement the processes described in ISO/IEC 27045 in order to ensure the security and privacy of big data. Scope The standard may “address the key challenges and risks of big data security and privacy”, providing guidance on how to: [Identify and] grade [evaluate?] big data security and privacy risks; Deploy [implement, use and manage] and maintain security and privacy controls [and other risk treatments?]; Validate and verify big data security and privacy arrangements [to gain assurance]. The audiences include: “software and hardware providers to securely construct a big data framework”; “application operators [service providers??] to securely maintain a big data framework”; “data providers and consumers to securely realize big data functions [??]; “industry to improve robustness and efficiency at the ecosystem level [??] to improve compatibility and inter-operation, to diversify choices of security products and to reduce redundant cost on security”. [from the 4th Working Draft ]. ISO/IEC 20547-4 “Information technology - Big data reference architecture - Part 4: Security and privacy” is cited as a normative (essential) reference. Structure The standard may guide big data security and privacy planners, managers, implementers, operators and auditors, through a lifecycle sequence of big data: Collection - data are amassed from internal/corporate and external systems; Transmission - data pass between networks; Storage - stored in massive database systems, perhaps in the cloud; Processing - manipulating and analysing big data to gain useful insight; Exchange - information passes between organisations; and Destruction - securely and permanently destroying big data. The applicable information security and privacy controls vary across the lifecycle, and are described succinctly in the standard through a set of succinct action-oriented statements (e.g . in the big data transmission stage, one control is to “check the integrity of the transmitted data” ... with no further guidance about why that may be important nor how to do it). In effect, the standard is a generic checklist of suggested/potential controls to consider, adapt and adopt. Status The standard development project commenced in 2019 and reached C ommittee D raft stage before being halted due to the rebooting of the ISO/IEC 27045 project in 2023, returning to the P reliminary W ork I tem stage. It is unlikely to surface before ISO/IEC 27045 is published in 2027 - so maybe 2028? Commentary The definition of ‘big data’ in the draft standard did not (in my personal, rather jaundiced and cynical opinion) reflect its widespread use in the IT industry at present, mostly because of the vagueness of ‘extensive’ which is essentially synonymous with, and adds little clarity to, plain ‘big’. I find Wikipedia more helpful e.g. : “Current usage of the term big data tends to refer to the use of predictive analytics, user behavior analytics, or certain other advanced data analytics methods that extract value from data, and seldom to a particular size of data set. "There is little doubt that the quantities of data now available are indeed large, but that's not the most relevant characteristic of this new data ecosystem." Analysis of data sets can find new correlations to "spot business trends, prevent diseases, combat crime and so on." Scientists, business executives, practitioners of medicine, advertising and governments alike regularly meet difficulties with large data-sets in areas including Internet searches, fintech, urban informatics, and business informatics. Scientists encounter limitations in e-Science work, including meteorology, genomics, connectomics, complex physics simulations, biology and environmental research.” For me, one of the defining characteristics of big data is that typical (mostly relational) database management systems struggle or are unable to cope with the complexity and dynamics/volatility of truly massive data sets. Beyond the limits of their scalability, conventional architectures experience constraints and failures, no matter how much raw CPU power is thrown at the problems. That implies the need for fundamentally different approaches and I rather suspect entails novel information risks and hence security/privacy controls. However, it remains to be seen what this standard will actually address in practice: this is cutting-edge stuff. I’m not sure how this standard will differ from and add value to the existing standard ISO/IEC 20547-4:2020 . The draft standard is not explicitly risk-driven: as shown above with a big data transmission control example, it simply recommends a bunch of security and privacy controls without clarifying the “key challenges and [information] risks” they are intended to mitigate - hence users of the standard may not appreciate their relative importance and relevance to the business, or to relevant compliance obligations and conformity requirements. Up Up Up This page last updated: 10 July 2026
