top of page

Search Results

125 results found with an empty search

  • ISO/IEC 27004 | ISO27001security

    Back Up Next ISO/IEC 27004 ISO/IEC 27004:2016 — Information technology — Security techniques — Information security management ― Monitoring, measurement, analysis and evaluation (second edition) Up Abstract “ISO/IEC 27004:2016 provides guidelines intended to assist organisations in evaluating the information security performance and the effectiveness of an information security management system in order to fulfil the requirements of ISO/IEC 27001:2013, 9.1. It establishes: (a) the monitoring and measurement of information security performance; (b) the monitoring and measurement of the effectiveness of an information security management system (ISMS) including its processes and controls; [and] (c) the analysis and evaluation of the results of monitoring and measurement.” [Source: ISO/IEC 27004:2016] Introduction ISO/IEC 27004 concerns measurements or measures needed for information security management: these are commonly known as ‘security metrics’ in the profession (if not within ISO/IEC JTC 1/SC 27!). Scope The standard is intended to help an organisation evaluate the effectiveness and efficiency of its I nformation S ecurity M anagement S ystem, providing information necessary to manage and (where necessary) improve the ISMS systematically. It expands substantially on Clause 9.1 of ISO/IEC 27001 concerning ‘monitoring, measurement, analysis and evaluation’. Structure Main clauses: 4: Structure and overview - this standard supports and relates to ISO/IEC 27001 ; 5: Rationale - explains the value of measuring things e.g. to increase accountability and performance; 6: Characteristics - what to measure, monitor, analyse and evaluate, when to do it, and who should do it; 7: Types of measures - performance (efficiency) and effectiveness measures; 8: Processes - how to develop, implement and use metrics. Annex A is where most of the theoretical measurement model from the first edition of the standard now languishes. Annex B catalogs 35 metrics examples of varying utility and quality, using a typical metrics definition form. Annex C demonstrates a pseudo-mathematical way to describe a metric, or rather an ‘effectiveness measurement construct’ (!). Status The first edition was published in 2009 . It had a distinctly academic/theoretical style. A substantially revised (rewritten) second edition was published in 2016 . It is more practical. Work is under way on a third edition. The committee plans to: Update the main body and appendix references to reflect the 2022 editions of ISO/IEC 27001 , ISO/IEC 27002 and ISO/IEC 27005 . Adopt ISO’s version of plain English . This may involve extensive wording changes to make the standard easier to understand and apply. Provide additional metrics examples to suit organisations of all sizes. If all goes to plan, the third edition will be published before 2028. Commentary Since a management system is literally worse than useless without suitable metrics, it is appropriate for ISO/IEC 27001 to list this standard as a normative or essential standard. More than that, information security metrics are of value in all organisations, whether they have an ISO27k ISMS in place or not. I understand why ISO/IEC 27004 and several other ISO27k standards are aligned specifically to ISO/IEC 27001 : the narrow scope and tight focus increases the chances of the standards being completed and published in a reasonable timeframe (a problem that plagued the first edition of ISO/IEC 27004). That leaves a gap for broader-scope standards, including a general purpose information risk and security metrics standard ... or indeed an entire book . The example metrics in Annex B of the current second edition are a mixed bunch, poorly described. Please don’t think that you ought to be using them in your ISMS, unless they happen to address your specific management information needs. There are lots of moving parts to an ISMS, numerous objectives and hence plenty of measurable aspects. For example, the incident management process has numerous measureable parameters or factors at each of its eight phases: Prepare : readability of policies and procedures; team size, competencies; salaries. Identify : call-out rate; near-misses reported; Assess : incident breakdowns by type, severity etc .; Contain : investigation costs; business disruption; Investigate : incident root causes; causative factors; Resolve : impacts; time from occurrence to closure; repair costs; Learn : post-incident reviews completed; recurrent/persistent issues; actions arising; Overall : incident management process effectiveness and efficiency. The German standards body, DIN, suggested introducing the GQM (G oal-Q uestion-M etric) approach into the standard - an excellent idea raised too late for the second edition. Unfortunately, it seems the current revision is once again missing the opportunity for this worthwhile improvement. Meanwhile, Lance Hayden’s book “IT Security Metrics ” ably explains using GQM to identify possible metrics, while “PRAGMATIC Security Metrics ” by Brotby and Hinson describes a systematic method to evaluate them and improve their quality and value. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27402 | ISO27001security

    Back Up Next ISO/IEC 27402 ISO/IEC 27402:2023 — Cybersecurity — IoT security and privacy — Device baseline requirements [first edition] Up Abstract ISO/IEC 27402 "provides baseline requirements for IoT devices to support security and privacy controls.” [Source: ISO/IEC 27402:2023] Introduction ISO/IEC 27400 describes commonplace information risks relevant to consumer and industrial IoT devices (things ) plus the associated network/cloud services, introducing the corresponding ICT security and privacy controls for the manufacturers and the users. In practice, however, as insecure things have been proliferating rapidly, the risks have generally increased. As an international standard, ISO/IEC 27402 is intended to ensure that all things at least provide a common set of foundational capabilities and functionality. IoT manufacturers using the suggested information risk management processes can build upon the standardised foundation, providing additional controls addressing the information risks relevant to various industrial and consumer applications. Scope The standard concerns basic information security and privacy controls for things . Structure Main clauses: 4: Overview - 1 paragraph 5: Requirements - for a cybersecurity and privacy baseline Annex: Risk management guidance based on ISO 31000 Status The current first edition was published in 2023 . Commentary The sheer scale, variety and rate of change in IoT makes developing information security and privacy standards challenging and yet important, arguably essential. Rapid innovation and intense market pressures on manufacturers seem unlikely to lead to voluntary adoption of this standard without additional factors (which are beyond the scope of the standard and ISO) ... unless a sufficient proportion of industrial and general consumers start inquiring about the security and privacy controls for IoT, voting with their budgets and wallets. The approach taken is to specify only a few fundamental information security and privacy controls in this ‘horizontal’ baseline standard (such as an information risk management process involving the identification, evaluation and treatment of information risks), with the intention of developing further standards specifying additional requirements for particular industry ‘verticals’, building on the generic baseline. It is anticipated that additional security controls will be required and defined in further standards for specific applications (e.g. for medical or vehicular things ). Noticeably absent from SC 27’s strategy (at present) are standards for implementing, using, managing, monitoring and administering IoT devices securely. The committee has thus far focused on getting appropriate security and privacy controls specified. As the controls are gradually designed and integrated into things (hopefully!), advice on the associated operational aspects may yet follow (possibly!). Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27011 | ISO27001security

    Back Up Next ISO/IEC 27011 ISO/IEC 27011:2024 / ITU-T X.1051 — Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for telecommunications organizations (third edition) Up Abstract “The scope of this Recommendation | International Standard is to provide guidelines supporting the implementation of information security controls in telecommunications organizations. The adoption of this Recommendation | International Standard will allow telecommunications organizations to meet baseline information security management requirements of confidentiality, integrity, availability and any other relevant information security property.” [Source: ISO/IEC 27011:2024/ITU-T X.1051] Introduction This I nformation S ecurity M anagement S ystem implementation guide for the telecoms industry was developed jointly by ITU-T and ISO/IEC JTC 1/SC 27, with the identical text being dual-numbered as both ISO/IEC 27011 and ITU-T X.1051 . Scope ISO/IEC 27011 guides telecoms organisations on the information security controls worth considering and adopting to mitigate their unacceptable information risks. As with ISO/IEC 27002 , the controls are discretionary, not mandatory. Telecoms organisations are free to determine whether the controls are or are not applicable ("necessary") according to their information risks, and they may prefer custom versions, bespoke controls or controls suggested by other sources. Ideally, they would do so using an I nformation S ecurity M anagement S ystem modeled on ISO/IEC 27001 , managing and overseeing the controls and risks systematically. Structure Aside from minor variations/explanations to a few of the ISO/IEC 27002 controls, the ‘extended control set’ suggests 14 additional information security controls specifically for telecoms organisations. Main clauses: 4: Overview 5: Organizational controls - with 8 supplementary controls 6: People controls - with no supplementary controls 7: Physical controls - with 5 supplementary controls 8: Technological controls - - with 1 supplementary control For example, control 5.42 TEL - Non-disclosure of communications indicates that telecoms organisations should, if appropriate, secure metadata relating to the messages they handle for customers, as well as the messages themselves, unless they are legally obliged to disclose. Status The first edition was published in 2008 . The second edition was published in 2016 with minor corrigendum (correction) in 2018. Having been updated and substantially restructured to align with the 2022 version of ISO/IEC 27002 , the current third edition was published in 2024 . Commentary It is good to see continued productive collaboration between these well-respected international standards bodies, despite the challenge and delays caused by batting the draft standard back and forth between their formal processes like a tennis ball at a Wimbledon final. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27007 | ISO27001security

    Back Up Next ISO/IEC 27007 ISO/IEC 27007:2020 — Information security, cybersecurity and privacy protection — Guidelines for information security management systems auditing (third edition) Up Abstract ISO/IEC 27007 "provides guidance on managing an information security management system (ISMS) audit programme, on conducting audits, and on the competence of ISMS auditors, in addition to the guidance contained in ISO 19011. [ISO/IEC 27007] is applicable to those needing to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme.” [Source: ISO/IEC 27007:2020] Introduction ISO/IEC 27007 provides guidance for internal auditors, external/third party auditors (e.g. those performing supplier security assessments) and others auditing ISMSs against ISO/IEC 27001 i.e. auditing the M anagement S ystem for conformity with the standard. For C ertification B odies' conformity assessors, it supplements or complements the mandatory accreditation requirements specified formally in ISO/IEC 27006-1 with additional discretionary advice. The standard covers the process of ISMS-specific conformity assessment or auditing, emphasising the 'management system' elements: Managing the ISMS audit programme (determining what to audit, when and how; assigning appropriate auditors; managing audit risks; maintaining audit records; continuous process improvement); Performing an ISMS MS audit (audit process - planning, conduct, key audit activities including fieldwork, analysis, reporting and follow-ups); Managing ISMS auditors (competencies, skills, attributes and evaluation). Scope "[ISO/IEC 27007] provides guidance on managing an information security management system (ISMS) audit programme, on conducting audits, and on the competence of ISMS auditors, in addition to the guidance contained in ISO 19011 . [ISO/IEC 27007] is applicable to those needing to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme." [Source: ISO/IEC 27007:2020] Structure Main clauses: 4: Principles of auditing 5: Managing an audit programme 6: Conducting an audit 7: Competence and evaluation of auditors Annex A: Guidance for ISMS auditing practice - includes advice re the documentation required by ISO/IEC 27001:2013 such as the S tatement o f A pplicability. The main body of the standard mostly advises on the application of ISO 19011 to the ISMS context, with a few not-terribly-helpful explanatory comments (e.g . audits are likely to involve sensitive proprietary or personal information, hence auditors may need to be security-cleared to the appropriate level before auditing, and to secure audit evidence appropriately). However the more valuable annex describes specific audit tests concerning the organisation’s conformity with the requirements of ISO/IEC 27001 . Status The first edition was published in 2011 . The second edition was published in 2017 . The current third edition was published in 2020 . A fourth edition is in the works, belatedly reflecting ISO/IEC 27001:2022 and the imminent release of ISO 19011:2026 . ISO 19011 :2026 is expected to provide guidance on remote auditing (e.g . of virtual locations such as globally-distributed data centres providing cloud services) plus other editorial changes to the current version. Publication of the fourth edition of ISO/IEC 27007 is planned for 2027. It is at C ommittee D raft stage, coming along nicely. Reviewers seek to align the terminology and concepts more closely with ISO/IEC 27000 , 27001 , 27003 and 27005 , for example not implying, suggesting or stating additional requirements beyond those formally stated in 27001 . Additional approaches, guidance and options are fine so long as readers (implementers and auditors) are not led to believe that they must do a load of additional things in order to conform to 27001 . Flexibility is valuable for such a broadly-applicable approach. Additional constraints or demands are not. Commentary As with ISO/IEC 27006-1 , this standard primarily concerns conformity or compliance auditing , a particular form of auditing with a specific goal: to determine whether the audited organisation’s ISMS conforms with (i.e. fulfills all the mandatory requirements specified formally by) ISO/IEC 27001 . Such audits are primarily performed for certification purposes. Other types of audits have different assurance goals. Please don’t make the mistake of assuming that all auditors are so-called “tick-and-bash” compliance/conformity auditors, or that all audits are compliance/conformity audits! Specifically in relation to information risk and security management, competent technology auditors might for instance: Evaluate the organisation’s strategies and policies relating to information and privacy risk management, incident management, fraud etc. for aspects such as strategic fit, currency, relevance, readability, coverage, suitability and quality (fitness for purpose); Audit workers’ conformity with organisational policies, procedures, directives, guidelines, employment contracts etc. , in the general area of information risk, information security and privacy; Delve into the root causes of ongoing issues and repetitive incidents, including near-misses and lesser events; Examine the governance arrangements in this area e.g. organisational structure, internal and external reporting relationships, information flows within and between management layers, accountabilities, roles and responsibilities ...; Audit the organisation’s compliance/conformity with other relevant obligations and expectations, apart from ISO/IEC 27001 e.g. privacy and data protection, intellectual property protection, health and safety, and employment laws and regulations; fire codes and building standards; technical security standards and protocols; supplier, partner and customer agreements and contracts; industry guidelines; ethical codes ... including the associated arrangements such as enforcement actions, and how the organisation stays up-to-date with changes in the requirements; Audit the effectiveness and efficiency of the ISMS, including aspects such as the net value (benefits less costs) it generates for the business, and releasing any unrealised potential; Examine ‘assurance’, ‘integrity’, ‘confidentiality’, ‘availability’, ‘risk’, ‘information risk management’, ‘compliance’, ‘privacy’ etc. in the broad, deliberately interpreting such words and phrases very widely to take in related aspects that are not usually considered in any depth; Review improvements made and explore further opportunities to improve the ISMS; Examine the organisation’s potential and actual exploitation of other standards, methods and frameworks relating to information risk and security management; Survey, compare and contrast various stakeholders’ opinions , comments and suggestions on the ISMS, teasing-out and addressing deeper, longstanding concerns and points of common interest that might otherwise remain hidden; Follow-up on previous ISMS audits, reviews, penetration tests, security assessments, post incident reports etc. , delving deeper into areas of concern, extending the scope and picking up on recurrent or widespread issues; Examining assurance management e.g. the manner in which various audits or assessments are scoped, approved, resourced, conducted, reported, actioned and closed off, treating ISMS or technology audits as important examples; Explore the management aspects of business continuity and resilience ; Look into the integration and interoperability of various management systems such as the ISMS; Audit the organisation’s information management as a whole, such as the integration of risk and security aspects with other business imperatives, and the proactive exploitation of information despite various risks; Benchmark the ISMS against comparable organisations or business units, or against other operational management systems e.g. quality assurance, environmental protection; Measure and comment on the organisation’s maturity in this general area; Review the organisation’s use of security metrics , reports and other management information. Although that is not even a complete list, there are clearly plenty of creative possibilities here, in addition to the basic conformity-assessment tick-n-bash approach. One of the best things about auditing is the chance to do something different for a change. Exploit the auditors’ independence, competence, experience, skills, focus, information access, rigorous methods, trustworthiness, access to senior management etc. to delve into aspects that are rarely if ever addressed as part of routine management and operations - potentially including those awkward politically-charged issues that are studiously avoided, and longstanding problems that seem destined to remain, forever. Some pessimists see audits as information threats to be avoided or minimised: speaking as a former (lapsed? Reformed!) IT auditor and optimist (realist!), I see audits as valuable business opportunities to be exploited to the max. Make the best of them. Milk the value. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TS 27100 | ISO27001security

    Back Up Next ISO/IEC TS 27100 ISO/IEC TS 27100:2020 — Information technology — Cybersecurity — Overview and concepts (first edition) Up Abstract ISO/IEC TS 27100 "provides an overview of cybersecurity. [It]: describes cybersecurity and relevant concepts, including how it is related to and different from information security; establishes the context of cybersecurity; does not cover all terms and definitions applicable to cybersecurity; and does not limit other standards in defining new cybersecurity-related terms for use.” [Source: ISO/IEC TS 27100:2020] Introduction According to this T echnical S pecification: “[ISO/IEC TS 27100] defines cybersecurity, establishes its context, and describes relevant concepts, including how cybersecurity is related to and different from information security. Cybersecurity concerns managing information security risks when information is in digital form in computers, storage and networks. Many of the information security controls, methods, and techniques can be applied to manage cyber risks.” Scope Overview of cybersecurity: the standard explains various terms and concepts relating to cyber security and cyber risk management, contrasting them against information risk and security management. "Cybersecurity is a broad term used differently through the world ... Cybersecurity focuses on the risks in cyberspace, an interconnected digital environment that can extend across organizational boundaries, and in which entities share information, interact digitally and have responsibility to respond to cybersecurity incidents." [Source: ISO/IEC TS 27100:2020] Structure Main clauses: 4: Concepts 5: Relationship between cybersecurity and relevant concepts 6: Risk management approach in the context of cybersecurity 7: Cyber threats 8: Incident management in cybersecurity Annex A: A layered model representing cyberspace Status The current first edition of this T echnical S pecification was published in 2020 and confirmed unchanged in 2024. Commentary See ISO/IEC 27032 . It seems to me two ‘cyber’ worlds coexist on parallel planes: Critical national infrastructure: within the realm of government and defence, a significant concern is to protect the nation’s water, power, comms, financial systems, food supplies etc. from substantial attacks by highly capable and determined foreign powers, terrorists or whatever through the Internet. Scary stuff! Those nations that are actively developing offensive capabilities in this area have a vested interest in other nations not developing their defensive capabilities ... hence I suspect some may be deliberately spreading confusion and frustrating attempts to bring clarity to this area among potential targets (through this international standard, for instance). It could be a delaying tactic. However, I may be a semi-paranoid conspiracy theorist. Plain old IT security, network security and Internet security in particular : protecting digital data in general against deliberate attacks. This is the everyday world, a subset of information security in fact. Move along please, nothing much to see here. Rather than clarifying the concepts and terminology, advancing the field, the standard muddies the waters - possibly the desired outcome of #1 above. Thankfully, it is just 17 pages and I suspect is destined to become a little-known cul de sac off the information superhighway, despite the project team’s desire for ISO to promote it as a substantial contribution. They claimed “cybersecurity is simply an evolution of information security” and that the standard “provides much needed explanation in the environment of general confusion about the differences and similarities between cybersecurity and information security”: ‘in the environment of general confusion’ is a curious way of putting it. Ironic, that, for a standard that was meant to clarify things ... Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27050-4 | ISO27001security

    Back Up Next ISO/IEC 27050-4 ISO/IEC 27050-4:2021 — Information technology — Electronic discovery — Part 4: Technical readiness (first edition) Up Abstract ISO/IEC 27050 part 4 “provides guidance on the ways an organization can plan and prepare for, and implement, electronic discovery from the perspective of both technology and processes. [Part 4] provides guidance on proactive measures that can help enable effective and appropriate electronic discovery and processes. [Part 4] is relevant to both non-technical and technical personnel involved in some or all of the electronic discovery activities.” [Source: ISO/IEC 27050-4:2021 ] Introduction In 35 pages, part 4 describes "technical readiness" (defined as "having the knowledge, skills, processes and technologies needed to address a particular issue or challenge") in the context of eDiscovery and eForensics. It covers the selection, preparation and use of tools supporting each step of the electronic discovery process, including the retention/storage, production and eventual destruction of E lectronically S tored I nformation. Scope Guidance on preparing the technology (i.e. the forensic tools and systems supporting the collection, storage, collation, searching, analysis and production of ESI, plus the related processes) and the associated processes required for eDiscovery. Note: 'technical' and 'technological' are, technically, different words with different meanings. Structure Main clauses: 6: Technical readiness 7: Readiness for electronic discovery 8: Additional considerations 9: Electronic discovery cross-cutting aspects Annex A: ESI storage questionnaire Status The current first edition was published in 2021 . Commentary As usual for ISO standards, part 4 offers generic advice and does not specify or recommend specific tools for eDiscovery. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27033-6 | ISO27001security

    Back Up Next ISO/IEC 27033-6 ISO/IEC 27033-6:2016 Information technology — Security techniques — Network security — Part 6: Securing wireless IP network access (first edition) Up Abstract ISO/IEC 27033 part 6 “describes the threats, security requirements, security control and design techniques associated with wireless networks. It provides guidelines for the selection, implementation and monitoring of the technical controls necessary to provide secure communications using wireless networks. The information in [part 6] is intended to be used when reviewing or selecting technical security architecture/design options that involve the use of wireless network in accordance with ISO/IEC 27033-2. Overall, ISO/IEC 27033-6 will aid considerably the comprehensive definition and implementation of security for any organization's wireless network environment. It is aimed at users and implementers who are responsible for the implementation and maintenance of the technical controls necessary to provide secure wireless networks.” [Source: ISO/IEC 27033-6:2016] Introduction This is a generic wireless network security standard offering basic advice for WiFi, Bluetooth, 3G and other wireless networks. Scope Risks, design techniques and control issues for securing IP wireless networks. Relevant to those involved in the detailed planning, design and implementation of security for wireless networks (e.g. network architects and designers, network managers and network security admins). Structure Main clauses: 6: Overview 7: Security threats 8: Security requirements 9: Security controls 10: Security design techniques and considerations Annex A: Technical description of threats and countermeasures Status The current first edition of part 6 was published in 2016 and confirmed unchanged in 2021. Commentary The standard uses the curious term “wire line network”, more commonly known as a wired network. The standard repeatedly refers to “access network”, another curious term that is not defined (aside from Radio Access Network). I guess it may simply mean “network” but without a definition, I cannot be sure. The standard indicates that encryption is an integrity control, whereas normally other cryptographic controls and protocols provide the integrity functions, while encryption provides confidentiality. Yes, I'm splitting hairs here ... over an integrity failure. Similarly to Part 7 , this part lists a number of “threats” which are, in fact, attack modes or incident scenarios. The list would, I feel, have been more useful if the standard systematically addressed each of them, explaining how certain controls mitigate them. It doesn’t. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27033-2 | ISO27001security

    Back Up Next ISO/IEC 27033-2 ISO/IEC 27033-2:2012 Information technology — Security techniques — Network security — Part 2: Guidelines for the design and implementation of network security (first edition) Up Abstract ISO/IEC 27033 part 2 “gives guidelines for organizations to plan, design, implement and document network security.” [Source: ISO/IEC 27033-2:2012] Introduction Part 2 revised and replaced ISO/IEC 18028 part 2. Defines a network security architecture for providing end-to-end network security. The architecture can be applied to various kinds of networks where end-to-end security is a concern and independently of the network's underlying technology. Scope Planning, designing, implementing and documenting network security. Objective: “to define how organisations should achieve quality network technical security architectures, designs and implementations that will ensure network security appropriate to their business environments, using a consistent approach to the planning, design and implementation of network security, as relevant aided by the use of models/frameworks. (In this context, a model/framework is used to outline a representation or description showing the structure and high level workings of a type of technical security architecture/design)” . Structure Main clauses: 6: Preparing for design of network security 7: Design of network security 8: Implementation Annex A: Cross-references between ISO/IEC 27001:2005 /ISO/IEC 27002:2005 network security-related controls and ISO/IEC 27033-2:2012 clauses Annex B: Example documentation templates Annex C: ITU-T X.805 framework and ISO/IEC 27001:2005 control mapping Status ISO/IEC 27033-2 revised and replaced ISO/IEC 18028-2. The current first edition of part 2 was published way back in 2012 and confirmed unchanged in 2018. It is now seriously out of date, referring to old editions of other standards and missing out on current networking security issues such as cloud security and virtual networking. Commentary Defines a network security architecture for providing end-to-end network security. The architecture can be applied to various kinds of networks where end-to-end security is a concern and independently of the network's underlying technology. Serves as a foundation for detailed recommendations on end-to-end network security. Covers risks, design, techniques and control issues. Refers to other parts of ISO/IEC 27033 for more specific guidance. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27036-1 | ISO27001security

    Back Up Next ISO/IEC 27036-1 ISO/IEC 27036-1:2021 — Cybersecurity — Supplier relationships — Part 1: Overview and concepts (second edition) Up Abstract ISO/IEC 27036 part 1 “is an introductory part of ISO/IEC 27036. It provides an overview of the guidance intended to assist organizations in securing their information and information systems within the context of supplier relationships. It also introduces concepts that are described in detail in the other parts of ISO/IEC 27036. [ISO/IEC 27036] addresses perspectives of both acquirers and suppliers.” [ ISO/IEC 27036-1:2021 ] Introduction ISO/IEC 27036 is a multi-part standard offering guidance on the management of information risks involved in the acquisition of IT products (goods and services) from suppliers. The standards avoid referring to selling and buying since the issues are much the same whether the transactions are commercial or not e.g . when one part of an organisation or group acquires IT products from another, or uses free/open-source products. Scope Part 1 introduces all parts of this standard, providing general background information such as the key terms and concepts around information security in supplier relationships, including “any supplier relationship that can have information security implications, e.g. information technology, healthcare services, janitorial services, consulting services, R&D partnerships, outsourced applications (ASPs), or cloud computing services (such as software, platform, or infrastructure as a service). ” Structure Main clauses: 5: Problem definition and key concepts 6: Overall ISO/IEC 27036 structure and overview Status The first edition of part 1 was published and made available for free in 2014. The current second edition was published initially for free in 2021 but no longer, unfortunately. Commentary Part 1 outlines a number of information risks commonly arising from or relating to business relationships between acquirers and suppliers, where goods/services acquired have an information content or information security relevance, or where the supplier gains access to the acquirer’s internal information. [The converse situation - i.e. acquirers gaining access to suppliers’ internal information - is not explicitly mentioned in part 1 but is noted in part 2 .] The standard primarily takes the perspective of the acquirer, covering the acquirer’s information security concerns that ought to be addressed in relationships with upstream suppliers. [The supplier’s information risks when supplying downstream customers, or in relationships with partners, are not explicitly covered e.g . disclosure and theft of sensitive intellectual property.] Within the ISO27k information security standards , the products most obviously covered by ISO/IEC 27036 include: IT outsourcing and cloud computing services; Other professional services e.g. legal, accounting/tax and HR services, security guards, cleaners, delivery services (couriers), equipment maintenance/servicing, consulting and specialist advisory services, knowledge management, research and development, manufacturing, logistics, source code escrow and healthcare; Provision of ICT hardware, software and services including telecommunications and Internet services; Bespoke products and services where the acquirer specifies the requirements and may play an active role in the product design and development (as opposed to commodities and standard off-the-shelf products); Electricity to power ICT equipment. The ISO/IEC 27036 standards therefore could cover: Strategic goals, objectives, business needs and compliance obligations in relation to information security, privacy and assurance when acquiring ICT-related or information products; Information risks such as: Acquirer’s reliance on providers, complicating the acquirer’s business continuity arrangements (both resilience and recovery); Physical and logical access to and protection of second and third party information assets; Creating an ‘extended trust’ environment with shared responsibilities for information security, or conversely applying the ‘zero trust’ approach in this context; Creating a shared responsibility for conformity with information security policies, standards, laws, regulations, contracts and other commitments/obligations; Coordination between supplier and acquirer to adapt or respond to new/changed information security requirements; ... and more. Information security controls such as: Preliminary analysis, preparation of a sound business case, Invitation To Tender etc ., taking into account the risks, controls, costs and benefits associated with maintaining adequate information security; Creation of explicit shared strategic goals to align acquirer and provider on information security and other aspects (e.g. a jointly-owned ‘relationship strategy’); Specification of important information security requirements (such as requiring that suppliers are ISO/IEC 27001 certified and/or use standards such as ISO27k ) in contracts, Service Level Agreements etc .; Security management procedures, including those that may be jointly developed and operated such as risk analysis, security design, identity and access management, incident management and business continuity; Special controls to cater for unique risks (such as testing and fallback arrangements associated with the transition/implementation stage when an outsourcing supplier first provides services); Clear ownership, accountability and responsibility for the protection of valuable information assets, including security logs, audit records and forensic evidence; A ‘right of audit’ and other compliance/assurance controls, with penalties or liabilities in case of identified non-compliance, or bonuses for full compliance; ... and more. The entire relationship lifecycle: Initiation - scoping, business case/cost-benefit analysis, comparison of insource versus outsource options as well as variant or hybrid approaches such as co-sourcing; Definition of requirements including the information security requirements, of course; Procurement including evaluating, selecting and contracting with supplier/s; Transition to or implementation of the supply arrangements, with enhanced risks around the implementation period; Operation including aspects such as routine relationship management, compliance, incident and change management, monitoring etc .; Refresh - an optional stage to renew the contract, perhaps reviewing the terms and conditions, performance, issues, working processes etc. ; Termination and exit i.e. ending a business relationship that has run its course in a controlled manner, perhaps leading back to the start. Some - but not all - of this is covered by ISO/IEC 27036, potentially leaving gaps to be filled by other standards plus corporate strategies, policies and procedures. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27561 | ISO27001security

    Back Up Next ISO/IEC 27561 ISO/IEC 27561:2024 — Information security, cybersecurity and privacy protection — Privacy operationalisation model and method for engineering (POMME) ( first edition) Up Abstract “This guidance document [ISO/IEC 27561] describes a model and method to operationalize the privacy principles specified in ISO/IEC 29100 into sets of controls and functional capabilities. The method is described as a process that builds upon ISO/IEC/IEEE 24774. [ISO/IEC 27561] is designed for use in conjunction with relevant privacy and security standards and guidance which impact privacy operationalization. It supports networked, interdependent applications and systems. [ISO/IEC 27561] is intended for engineers and other practitioners developing systems controlling or processing personally identifiable information.” [Source: ISO/IEC 27561:2024] Introduction The standard presents a systematic approach for engineering IT systems to satisfy privacy and personal data protection requirements, drawing on the 11 privacy principles expressed in ISO/IEC 29100 privacy framework plus ISO/IEC TR 27550 and ISO/IEC TR 27555 privacy engineering for system lifecycle processes. Scope The standard is intended to help ‘privacy engineers’ (or system architects or technical managers) interpret and satisfy the privacy requirements expressed in policies etc . plus those that emerge in the course of further analysis and development. It lays out a structured analytical method and model based on OASIS, emphasising functional architecture and practical implementation of privacy engineering. The process involves elaborating on privacy risks and designing controls, capabilities required plus the functions and mechanisms to deliver them. Structure Main clauses: 5: Context of privacy operationalization - background to the model and approach. 6: Initial information inventory process - an iterative personal information inventory process including determination of the domains, processes, systems and data flows. 7: Privacy controls, privacy control requirements, capabilities, risk assessment and iteration process - determination and documentation of the required controls, functions, mechanisms etc. 8: Privacy capabilities - essentially the governance arrangements for addressing privacy. Annex A: Mapping of the privacy principles from ISO/IEC 29100 to POMME capabilities. Annex B: Lifecycle process example involving a PII controller and a solution provider. Annex C: POMME capability functions and mechanisms in a consumer application use case. Status The current first edition was published in 2024 . Commentary Despite the contrived title and nasty neologism ‘operationalization’, the standard’s systematic, structured approach should prove useful for privacy specialists. Up Up Up This page last updated: 10 July 2026

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page