top of page

Search Results

125 results found with an empty search

  • ISO/IEC 27019 | ISO27001security

    Back Up Next ISO/IEC 27019 ISO/IEC 27019:2024 — Information security, cybersecurity and privacy protection — Information security controls for the energy utility industry (second edition) Up Abstract ISO/IEC 27019 "provides information security controls for the energy utility industry, based on ISO/IEC 27002:2022, for controlling and monitoring the production or generation, transmission, storage and distribution of electric power, gas, oil and heat, and for the control of associated supporting processes. This includes in particular the following: central and distributed process control, monitoring and automation technology as well as information systems used for their operation, such as programming and parameterization devices; digital controllers and automation components such as control and field devices or programmable logic controllers (PLCs), including digital sensor and actuator elements; all further supporting information systems used in the process control domain, e.g. for supplementary data visualization tasks and for controlling, monitoring, data archiving, historian logging, reporting and documentation purposes; communication technology used in the process control domain, e.g. networks, telemetry, telecontrol applications and remote-control technology; Advanced metering infrastructure (AMI) components, e.g. smart meters; measurement devices, e.g. for emission values; digital protection and safety systems, e.g. protection relays, safety PLCs, emergency governor mechanisms; energy management systems, e.g. for distributed energy resources (DER), electric charging infrastructures, and for private households, residential buildings or industrial customer installations; distributed components of smart grid environments, e.g. in energy grids, in private households, residential buildings or industrial customer installations; all software, firmware and applications installed on above-mentioned systems, e.g. distribution management system (DMS) applications or outage management systems (OMS); any premises housing the abovementioned equipment and systems; remote maintenance systems for abovementioned systems.” [Source: ISO/IEC 27019:2024] Introduction This standard is intended to help organisations in “the energy utility industry” (such as conventional/non-nuclear electricity generators, plus suppliers of gas, oil and heating) to interpret and apply ISO/IEC 27002 in order to secure their industrial process control systems i.e. their O perational T echnology as opposed to I nformation T echnology. Scope Information security management presents fundamentally the same risk management challenges in all contexts, but the real-time nature of process control systems plus their associated safety and environmental criticality make some aspects particularly challenging for energy utilities. The standard therefore provides additional, more specific guidance on information security controls than the generic advice provided by ISO/IEC 27002 , tailored to the specific context of process control systems used by energy utilities for controlling and monitoring the production or generation, transmission, storage and distribution of electric power, gas, oil and heat, and for the control of associated supporting processes. Note: given their unique and extreme risks, the scope of ISO/IEC 27019 explicitly excludes process control in nuclear facilities. See instead (for example) IEC 63096:2020 “Nuclear power plants - Instrumentation, control and electrical power systems - Security controls” . Structure ISO/IEC 27019 complements and must be read in conjunction with ISO/IEC 27002:2022 since it does not incorporate the content of ISO/IEC 27002. A dozen additional controls are offered for the energy sector. Main clauses: 5: Organizational controls - with 2 supplementary controls 6: People controls 7: Physical controls - 4 supplementary controls 8: Technological controls - 6 supplementary controls Annex A: Energy utility industry specific controls reference Annex B: Correspondence between this document and the first edition (ISO/IEC 27019:2017) The standard notes in clause 0.4: “In addition to the controls provided by a comprehensive information security management system, [ISO/IEC 27019] provides additional assistance and sector-specific measures for the process control systems used by the energy utility sector, taking into consideration the special requirements in these environments. If necessary, further controls can be developed to fulfil particular requirements. The selection of controls depends upon the decisions taken by the organization on the basis of its own risk acceptance criteria, the options for dealing with the risk and the general risk management approach of the organization. NOTE National and international law, legal ordinances and regulations can apply.” Other ISO27k standards are also recommended to fill-in the broader context e.g. ISO/IEC 27001 for an overarching I nformation S ecurity M anagement S ystem that encompasses process control/OT as well as general commercial systems, networks and processes, plus ISO/IEC 27005 concerning the management of information risk. Status A preliminary edition was published as a T echnical R eport in 2013 by fast-tracking the German standard DIN SPEC 27009:2012-04 based on ISO/IEC 27002:2005. The first International Standard was published in 2017, based on ISO/IEC 27001:2013 and ISO/IEC 27002:2013, plus IEC TC 57 standards, IEC TC 65 standards (IEC 62443-2-1) and IEC SC45A standards (IEC 62645). A corrigendum to replace a stray “should” with a “shall” in the annex was published to critical acclaim in 2019. Hurrah! Crisis averted! The corrected standard was confirmed unchanged in 2022 ... but then was revised anyway to reflect the themed restructure and controls resequence of ISO/IEC 27002:2022 adding 12 suggested “ENR” controls to ISO/IEC 27022’s 96. The current second edition was published in 2024 . Commentary The global energy industry has long had a strong safety culture since the devastating physical impacts caused by explosions, oil and chemical spills, radioactive releases etc. are painfully apparent (Bhopal , Three Mile Island , Chernobyl , Exxon Valdiz , Deepwater Horizon , Fukoshima ... need we say more?). The industry also has a strong awareness of its environmental obligations both in terms of its own operations, the upstream primary industries (e.g. mining) and the downstream impacts of some of its products. F Furthermore, the industry has a strong culture of physical and information security due to the substantial risks arising from: Threats such as natural disasters and deliberate attacks (sabotage) from hackers, A dvanced P ersistent T hreats, spies and spooks, terrorists, insiders, pressure groups and foreign states, as well as more mundane threats from accidents, competitors, electromechanical failures, malware/ransomware, social engineers etc .; Vulnerabilities inherent in their systems and processes. Process control systems that are (in some manner) connected to, exposed to or accessible from the Internet and other networks are vulnerable to a panopoly of cyber-threats, including those resulting from design flaws and bugs in software especially if they are not well designed, managed and maintained (e.g . security patching is distinctly challenging on safety-critical systems, given the need for assurance that patches do not harm safety); and Impacts , particularly limited availability and/or integrity of business- or safety-critical information leading to supply interruptions (power cuts), out-of-specification supplies (e.g . over/under-voltage supplies), safety incidents (e.g . the catastrophic release of vast amounts of energy) and environmental incidents (e.g. oil/gas/chemical leaks). Energy utilities, both public and private, are generally classed as part of the critical national infrastructures (e.g. under NIS 2 in Europe) due to their obvious strategic significance. With an extremely high level of automation, the energy industry relies heavily on OT, principally electronic process control systems such as P rogrammable L ogic C ontrollers, I ndustrial I nternet o f T hings, I ndustrial C ontrol S ystems and S upervisory C ontrol A nd D ata A cquisition, plus the associated networks and procedures, to monitor, direct and control its production activities in real time. Most of the safety-related operations, for example, in a modern plant depend heavily on networked computer systems with electronic monitoring and electrically-operated valves, switches and actuators, while manually-operated controls are often limited to specific backup or emergency override functions. Many of the monitored and controlled systems are located in physically stressful locations subject to extreme heat, pressure, corrosion and/or vibration, and some are distributed remotely, sometimes very remotely, making physical access, monitoring and access control challenging and costly. In short, the industry cannot function normally and safely without its electronic process control systems and networks, while serious, widespread or extended incidents cause severe national if not international repercussions. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27050-1 | ISO27001security

    Back Up Next ISO/IEC 27050-1 ISO/IEC 27050-1:2019 — Information technology — Security techniques — Electronic discovery — Part 1: Overview and concepts (second edition) Up Abstract “Electronic discovery is the process of discovering pertinent Electronically Stored Information (ESI) or data by one or more parties involved in an investigation or litigation, or similar proceeding. [ISO/IEC 27050-1] provides an overview of electronic discovery ...” [Source: ISO/IEC 27050-1:2019 ] Introduction The fundamental purpose of the ISO27k digital forensics standards is to promote good practice methods and processes for forensic capture and investigation of digital evidence. While individual investigators, organisations and jurisdictions may well retain certain methods, processes and controls in compliance with local laws, regulations and established practices, it is hoped that standardization will (eventually) lead to the adoption of similar if not identical approaches internationally, making it easier to compare, combine and contrast the results of such investigations even when performed by different people or organisations and potentially across different jurisdictions. Scope Part 1 gives an overview of eDiscovery, defines the terms, concepts, processes etc . (such as E lectronically S tored I nformation), and introduces this multi-part standard. Structure Main clauses: 5: Overall structure and overview of the ISO/IEC 27050 series 6: Overview of electronic discovery 7: E lectronically S tored I nformation (ESI ) 8: Electronic discovery process 9: Additional considerations Status The first edition was published in 2016 . The current second edition was published in 2019 . Commentary This multi-part standard concerns the discovery phase, specifically the discovery of E lectronically S tored I nformation, a legal term-of-art meaning (in essence) forensic evidence in the form of digital data. Electronic discovery (eDiscovery) involves the following main steps: Identification: ESI that is potentially relevant to a case is identified, along with its locations, custodians, sizes/volumes etc. This can be more complex than it may appear, for instance involving information assets belonging not just to the individual suspects but also their employers, friends and other organisations such as phone companies and the suppliers of services such as email and Internet access (ISPs), even social media. Operational/online data, backups and archives may all contain relevant data. Often, this phase is time-critical since potential evidence (especially ephemeral operational data) may be spoiled or destroyed before it has been captured and preserved; Preservation: the identified, potentially relevant ESI is placed under a legal hold, starting the formalized forensic process designed to ensure, beyond doubt, that they are protected through the remaining steps against threats such as loss/theft, accidental damage, deliberate interference/manipulation and replacement/substitution, any of which might spoil, discredit and devalue the data, perhaps resulting in the ESI being ruled inadmissible or simply becoming unusable. The legal hold is essentially a formal obligation on the custodian not to interfere with or delete the ESI. Note: this may have implications on live systems since their continued operation may spoil the ESI; Collection: the ESI is collected from the original custodian, typically by physically removing the original digital storage media (hard drives, memory sticks and cards, CDs, DVDs, whatever) and perhaps associated physical evidence (such as devices, media storage cases, envelopes etc . that might have fingerprints or DNA evidence linking a suspect to the crime) into safe custody. In the case of Internet, cloud or other dispersed and ephemeral data including RAM on a running system, it may be impracticable or impossible to secure the data by capturing physical media, hence the data rather than the media may need to be captured directly in a forensically sound manner. Note: the original evidence may later be produced in court hence all subsequent forensic analysis must be performed in such a way that there is no credible possibility that it might have been spoiled e.g. by analysing bit-copies made with suitable forensic tools and methods rather than the original evidence itself. Note also that physically removing systems and media into the custody of a third party could itself be classed as an information security incident with clear implications on the confidentiality, integrity and availability of the information, particularly since, at this stage, the case is not proven: in other words, liabilities may be accumulating; Processing: forensic bit-copies are stored in a form that allows them to be searched or analysed for information that is relevant to the case, using suitable forensic tools and platforms. Sifting out the few vital bits of data from a much larger volume typically collected is the crux of this step; Review: forensic bit-copies are searched or analysed for information that is relevant to the case; Analysis: the information is further analysed and assessed as to its relevance, suitability, weight, meaning, implications etc. Useful information is gleaned from the selected data; Production: relevant information from the analysis, plus the original storage media etc. , is formally presented to the court as evidence. This inevitably involves demonstrating and explaining the meaning of the evidence in terms that make sense to the court. Hopefully, something along the lines of “I state, under oath, that we complied fully with ISO/IEC 27050” will, in future, side-step a raft of challenges concerning the eDiscovery processes! Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TS 27116-1 | ISO27001security

    Back Up Next ISO/IEC TS 27116-1 ISO/IEC TS 27116-1 — Information security, cybersecurity and privacy protection — Framework for customised and multipurpose evaluation [DRAFT] Up Abstract [ISO/IEC TS 27116-1] "defines a general framework for customized and multipurpose evaluation.” (!) [Source: Preliminary Work Item Oct 2025] Introduction ?? Scope ?? Structure [I don’t know what the ‘customised and multipurpose evaluations’ are for which this project intends to provide a 'general framework'. No idea, sorry.] Status A standard development project commenced in 2024, producing a P reliminary W ork I tem in October 2025. There is an open call to nominate experts by August 2026. Commentary Evaluation of what? Against what? Why? How? When? By whom? So many questions but next to no answers thus far. The dash-1 suggests this may be a multi-part standard. I have no idea what other parts are planned, if any. Evidently although SC 27 voted to proceed with this project, only 3 national bodies confirmed their active involvement, nominating experts ... so, unless further support arrives before early August, this project looks unlikely to proceed. Presumably someone thought it sufficiently worthwhile to launch the project: maybe it was ill-conceived or perhaps there is a genuine need, but maybe now is not the best time? Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TR 27024 | ISO27001security

    Back Up Next ISO/IEC TR 27024 ISO/IEC TR 27024 — Technical Report — Information security, cybersecurity and privacy protection — Information on government and regulatory use of information security standards [DRAFT] Up Abstract ISO/IEC TR 27024 "provides a list of national regulations that reference ISO/IEC 27001 as a requirement.” [Source: ISO/IEC JTC 1/SC 27 Committee Doc 11, May 2025] Introduction This T echnical R eport is meant to help determine which of the ISO27k standards (or rather "information security management system standards developed by ISO/IEC JTC 1/SC 27") are recommended or required for national compliance reasons (without being construed as legal advice), and to facilitate or encourage global harmonisation of the laws, regulations etc. in the field of information security management. Scope The T echnical R eport identifies laws, regulations and guidelines from a selection of countries that refer to ISO27k standards such as ISO/IEC 27001, 27002 and 27005, and explicitly concern: Information security Privacy/data protection Digitalisation and electronic archiving. Structure The main clause covers 20 countries (some of which are European) plus the European Union. Each one has a table: Citing reference document/s (mostly laws and regulations); Identifying the organisations that own/issued the reference documents (e.g. ministries); Stating which ISO27k standards are recommended or required; Plus comments explaining and expanding on the above. Status A T echnical R eport was prepared from ISO/IEC JTC 1/SC 27 S tanding D ocument 7 - an internal committee reference document. It is now at D raft T echnical R eport stage, having been submitted to the ISO secretariat for publication. It might even surface this year. Commentary Notably missing from the coverage list are the United States, China, Russia and all of Africa - in other words, this standard covers roughly a quarter of the globe. It's a start, I guess. Depending on how one interprets part 2 of the ISO Directives , this standard may be stillborn: "A document does not in itself impose any obligation upon anyone to follow it. However, an obligation can be imposed, for example, by legislation or by a contract which makes reference to the document. A document shall not include contractual requirements (e.g. concerning claims, guarantees, covering of expenses), or legal or statutory requirements." [clause 4] The standard progressed rapidly to D raft T echnical R eport stage and was planned for release way back in 2023. Patently, however, compiling and checking details on relevant laws and regs around the globe, along with editorial changes required by ISO, substantially delayed release. Under ISO/IEC's revised DIrectives and firm deadlines, this project would have been cancelled long ago. If this had remained a S tanding D ocument without the formalities of becoming a standard, it would have been easier, quicker and cheaper to update it as the referenced standards, laws and regs change, with the bonus of being freely available to those who need the information ... but in its infinite wisdom, the committee decided to publish (and consequently maintain) it as a T echnical R eport. The TR does not (explicitly) cover numerous other areas of law less directly/obviously concerned with the confidentiality, integrity or availability of information such as: Classified information and official secrets Contracts Cryptography Digital signatures Defence Family law Financial data integrity, reporting and accounting Forensics Fraud Governance Health and safety Intellectual property Medical records Misinformation Product quality/fitness for purpose Taxation ... nor more besides. Taking a broad perspective, there are clearly loads of laws and regs that have some relevance to the c onfidentiality, i ntegrity or a vailability of information. In the extreme, virtually every law involves forensic evidence with strong cia implications. Laws and regs relating to human safety are important to protect the valuable knowledge and competencies in our heads, while those relating to mental health affect our information processing capabilities. Laws and regs on tax and financial reporting and corporate governance all have information security implications. The standard is unlikely even to mention these, reflecting its arbitrary nature. This standards project faces a similar conundrum to ISO/IEC 27002 . It would be wonderful if the standard was truly comprehensive and up-to-date and could be relied upon as such, but ultimately that is infeasible. There is a risk that naive users may rely on the standard as definitive without seeking competent legal advice or researching (e.g. Googling) which laws and regs are in fact applicable - hopefully not you though, having read this cautionary note! Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27566-1 | ISO27001security

    Back Up Next ISO/IEC 27566-1 ISO/IEC 27566-1:2025 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 1: Framework [First edition] Up Abstract ISO/IEC 27566 part 1 "establishes a framework for age assurance systems and describes their core characteristics, including privacy and security, for enabling age-related eligibility decisions." [Source: ISO/IEC 27566-1:2025 ] Introduction This standard lays out the core principles and a framework for determining someone’s age or age-range independently of their identity, for use in age-related eligibility decisions. Scope Age assurance framework Structure Main clauses: 4: Overview of age assurance 5: Functional characteristics - functional requirements 6: Performance characteristics - assurance and metrics 7: Privacy characteristics - privacy requirements 8: Security characteristics - cybersecurity requirements 9: Acceptability characteristics - nondiscrimination requirements 10: Practice statements - documenting the arrangements Status The standard development project set out in 2022. The current first edition was published in 2025 . Commentary Whereas self-assertion (e.g. “Click here if you are an adult”) is a simple and commonplace but clearly pathetically weak control, the standard aims to standardise and where necessary strengthen the process of determining someone’s age or age-range without (necessarily) requiring them to disclose their identity and thereby risk compromising their privacy. The cunning grand plan is to develop and incorporate appropriate assurance controls systematically into the framework indicating confidence in the determined age or age-range, giving policy- and law-makers options when defining age-related criteria for various purposes. In situations where age is particularly important, additional confidence in the age determination is warranted, even if that implies completing a more involved and lengthy process of age verification, perhaps utilising a third party age-verification service or aggregating multiple age indicators (PII clustering?) taking account of any contraindications, inconsistencies or doubts. Conversely, if age verification is relatively unimportant, simpler, quicker, cruder approaches may suffice. Spoofing (e.g . where an older person pretends or claims to be, and completes the age-verification process on behalf of, a youngster, or a child simply presents a fake credential) is just one of the challenges relevant to users of this standard. There are also identities, credentials, tokens and age-verification subsystems and services, plus individual rights and freedoms to protect (such as privacy, of course, and inclusivity, prejudice and entitlement), in a framework that allows or encourages communication and collaboration between age-verifiers. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27403 | ISO27001security

    Back Up Next ISO/IEC 27403 ISO/IEC 27403:2024 — Cybersecurity — IoT security and privacy — Guidelines for IoT-domotics (first edition) Up Abstract ISO/IEC 27403 "provides guidelines to analyse security and privacy risks and identifies controls that can be implemented in Internet of Things (IoT)-domotics systems.” [Source: ISO/IEC 27403:2024] Introduction “Domotics” was originally known as home automation or “smart homes”, where domicile or home is described as “The private, hence highly customizable area where someone lives, alone or with guests or cohabitants” that “includes dedicated infrastructure aimed to support those individuals, such as healthcare and wellness systems, building control systems, smart metering and systems for entertainment or gaming.” Setting the standard for information security and privacy of IoT things intended for home use is quite a challenge given the variety of things , homes and living arrangements, security and privacy issues and controls. Rapid innovation and change in this area further complicates matters. Scope This cybersecurity standard is aimed squarely at the designers, manufacturers and security/privacy assessors of IoT domotics rather than the “users” (consumers/retail customers). It covers the information security and privacy aspects of device-device interactions (e.g. hubs and subsystems) as well as human-device plus device-sensors/actuators that physically interact with the home, and networking both within the home and beyond (e.g. via Internet gateways). Structure Main clauses: 5: Overview of the stakeholders (IoT device manufacturers, service providers, regulatory authorities and users), the lifecycles for IoT domotics developers, service providers and users, an architectural reference model, and an introduction to the ‘security’ (meaning cybersecurity) and privacy aspects. 6: Risk assessment guidelines covering cybersecurity and privacy risks (referring to eight other standards!). 7: ’Security’ and privacy controls. Annex A: Use cases - six examples of the principles in action. Annex B: ‘Security’ and privacy concerns of various stakeholders with differing perspectives. Annex C: Stakeholders’ security and privacy responsibilities. Annex D: ‘Security measures’ (cybersecurity and privacy controls) for various IoT domotics devices. Status The current first edition was published in 2024 . Commentary Whereas “IoT” is a common abbreviation, “domotics” is a neologism derived from domus (Latin for house) and robotics. Rather than simply recommending a bunch of controls, the standard describes typical information [security and privacy] risks relating to domotics, and recommend information security controls to mitigate them, making this a risk-based ISO27k standard. Sounds good in theory, although strictly speaking several of the ‘risks’ described in the draft are in fact weak or missing controls, not risks. Information risks provide the rationale, context or basis for the controls. Helping readers identify and consider the information risks should give them a better appreciation of what the information security controls are meant to achieve - the control objectives. The risks and the controls in the standard are examples to stimulate readers into considering the risks and control objectives in their particular contexts. Challenges (risks) in the home environment include: Limited information security awareness and competence by most people. IoT things are generally just black-boxes. Ad hoc assemblages of networked IT systems - including things worn/carried about the person (residents and visitors) and work things, not just things physically permanently installed about the home (e.g. smart heating controls, door locks and cat feeders). Things are not [always] designed for adequate security or privacy since other requirements (such as low price and ease of use) generally take precedence. Finite processing and storage capacities, plus limited user interfaces, hamper or constrain their security capabilities. Lack of processes for managing security and privacy systematically at home. Any such activities tend to be ad hoc /informal and reactive rather than proactive. Informality: the home is a relatively unstructured, unmanaged environment compared to the typical corporate situation. Few domotics users even consider designing a complete system, although certain aspects or subsystems may be intentionally designed or at least assembled for particular purposes (e.g . entertainment). Dynamics and diversity: people, devices and services plus the associated challenges and risks, are varied and changeable. The home is a fairly fluid environment. Limited ability to control who may be present in/near the home and hence may be interacting with IoT devices e.g. adult residents plus children, owners, visitors, installers, maintenance people, neighbours, intruders ... Physically securing things against accidental or malicious interaction (e.g. someone reading the label with the default password, hitting the reset button, damaging or stealing the device) is difficult. Limited ability to manage or control IoT device and service upstream supply chains, as well as the downstream installation, configuration, use, monitoring and maintenance of devices and services, with little if any coordination among the parties. Given their number, variety and significance, I believe conventional, structured and systematic information risk management is largely impracticable for domotics: there is way too much to do here! In accordance with the risk-based approach that underpins all the ISO27k standards, this standard prioritises some significant information risks, encouraging IoT device and service providers to play their parts - although even that is difficult since they are only providing parts of a complex and dynamic system. The bigger picture remains of concern. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27036-2 | ISO27001security

    Back Up Next ISO/IEC 27036-2 ISO/IEC 27036-2:2022 — Cybersecurity — Supplier relationships — Part 2: Requirements (second edition) Up Abstract ISO/IEC 27036 part 2 “specifies fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier and acquirer relationships. These requirements cover any procurement and supply of products and services, such as manufacturing or assembly, business process procurement, software and hardware components, knowledge process procurement, build-operate-transfer and cloud computing services ... To meet the requirements, it is expected that an organization has internally implemented a number of foundational processes or is actively planning to do so [such as] business management, risk management, operational and human resources management, and information security.” [Source: ISO/IEC 27036-2:2022 ] Introduction The controls recommended in part 2 cover various aspects of governance and business management (e.g. operations, HR management, IT management, relationship management, metrics) as well as information risk management (e.g. information risk analysis and treatment, security controls specification, security architecture/design, strategy). Scope Part 2 specifies fundamental information security requirements pertaining to business relationships between suppliers and acquirers of various products (goods and services). It helps them reach a common understanding of the associated information risks, and treat them accordingly to their mutual satisfaction. The introduction explicitly states that part 2 is not for certification despite having “Requirements” in the title and “shall” in the content [these are normally reserved words in ISO-land]. Structure Main clauses: 6: Information security in supplier relationship management 7: Information security in a supplier relationship instance Annex A: Correspondence between ISO/IEC/IEEE 15288 and this document Annex B: Correspondence between ISO/IEC 27002 controls and this document Annex C: Objectives from Clauses 6 and 7 Status The first edition of part 2 was published in 2014 . Following changes in ISO/IEC 15288 , the current second edition was published in 2022 . Commentary Although this is not intended to be a certifiable standard with formally-specified requirements that are mandatory for certification, wording along the lines of “The following minimum activities shall be executed by the acquirer to meet the objective defined at [a specific clause] ” leaves little latitude for organisations to interpret, adapt and apply the standard according to their particular business situations and needs, despite an explanatory note: ”The user of [ISO/IEC 27036-2] needs to correctly interpret each of the forms of the expression of provisions (e.g. “shall”, “shall not”, should” and “should not”) as being either requirements to be satisfied or recommendations where there is a certain freedom of choice.” It comes down to the business and legal arrangements in place between supplier and acquirer as to how much ‘freedom of choice’ there is in interpreting and applying this standard. In the absence of explicit, perfectly worded, unambiguous and binding contractual clauses, lawyers smile wryly and rub their hands together, their cartoon eyes rolling like an old fashioned cash register ... Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27071 | ISO27001security

    Back Up Next ISO/IEC 27071 ISO/IEC 27071:2023 — Cybersecurity — Security recommendations for establishing trusted connections between devices and services (first edition) Up Abstract ISO/IEC 27071 "provides a framework and recommendations for establishing trusted connections between devices and services based on hardware security modules. It includes recommendations for components such as: hardware security module, roots of trust, identity, authentication and key establishment, remote attestation, data integrity and authenticity. [ISO/IEC 27071] is applicable to scenarios that establish trusted connections between devices and services based on hardware security modules. [ISO/IEC 27071] does not address privacy concerns.” [Source: ISO/IEC 27071:2023] Introduction This standard concerns mutual authentication between distributed network devices (such as sensors and other IoT things ) and [cloud-based] information services, using P ublic K ey I nfrastructure and physical H ardware S ecurity M odules - complementing the virtual roots of trust described in ISO/IEC 27070 . Scope The standard lays out a conceptual framework for establishing trusted connections between devices and services based on HSMs with recommendations roots of trust, identity, authentication and key establishment, remote attestation, data integrity and authenticity. Structure Main clauses: 5: Framework and components for establishing a trusted connection - concepts and architectures 6: Security recommendations for establishing a trusted connection - brief descriptions of the information and physical security controls recommended to ensure that device-service connected are sufficiently secure, trusted and trustworthy. Annex A: Threats Annex B: Solutions for components of a trusted connection Annex C: Example of establishing a trusted connection The standard is admirably succinct. Status The current first edition was published in 2023 . Commentary Here is a fictitious scenario illustrating the need for mutual authentication. Imagine your electric car maintains detailed technical data about the places its has been driven to, the manner of driving, battery performance etc. You agree to share the data routinely with the vehicle manufacturer through cellular connections to a car monitoring app, in return for a warranty extension, driving tips or advanced warning of issues requiring a service visit. How does the manufacturer know the data uploaded by your car is, in fact, from your car, not a cloned or modified vehicle? How does your car know that the car monitoring app is, in fact, the car monitoring app run by the manufacturer, not some naughty hacker intent on discovering your movements and habits for blackmail or kidnap, or another car manufacturer snooping on its competitor’s technology, or an agent for the insurance companies illicitly checking on your driving competence and hence risk profile? Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TS 27115-3 | ISO27001security

    Back Up Next ISO/IEC TS 27115-3 ISO/IEC TS 27115-3 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 3: Security profiles [DRAFT] Up Abstract ?? Introduction Using concepts and terms in the style of the C ommon C riteria such as T arget O f E valuation and security profile, part 3 intends to explain how to evaluate a complex system against the security architecture. Scope ISO/IEC TS 27115-3 will provide a framework to describe security profiles based on ISO/IEC TS 27115-1 and ISO/IEC TS 27115-2 . The framework uses basic architecture concepts to enable the definition of architecture-based security profiles and composition of profiles. Structure ?? Status Part 3 is due out in 2029. It is currently at A pproved W ork I tem stage. Commentary TBA Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27102 | ISO27001security

    Back Up Next ISO/IEC 27102 ISO/IEC 27102:2019 — Information security management — Guidelines for cyber-insurance (first edition) Up Abstract ISO/IEC 27102 "provides guidelines when considering purchasing cyber-insurance as a risk treatment option to manage the impact of a cyber-incident within the organisation's information security risk management framework. ...” [Source: ISO/IEC 27102:2019] Introduction There is a global market for ‘cyber-insurance’, providing options for the transfer of some information/commercial risks to commercial providers. At present, the focus is primarily on sharing risk and providing compensation for the business costs and consequences arising from ‘cyber-incidents’ (such as serious privacy breaches caused by hacks and malware infections) that have not been entirely avoided, mitigated or simply accepted by the organisation. Scope This standard explains: Essential insurance concepts to information risk and security professionals; Essential cybersecurity concepts to insurance professionals; What the insurers and customers of cyber-insurance typically expect of each other; How to scope, determine, specify and procure appropriate cyber-insurance to managers, procurement and insurance sales professionals, and others involved in the negotiations and contracting process; The advantages and disadvantages, costs and benefits, constraints and opportunities in this area. Structure Main clauses: 5: Overview of cyber-insurance and cyber-insurance policy 6: Cyber-risk and insurance coverage 7: Risk assessment supporting cyber-insurance underwriting 8: Role of ISMS in support of cyber-insurance Annex A: Examples of ISMS documents for sharing Status The current first edition was published in 2019 . The second edition is at W orking D raft stage, refocusing on how cyber insurance can both support and draw upon an ISMS, and updating to reflect the current 2022 versions of ISO/IEC 27001 and 27002. A new title has been approved (“Guidelines for the use of ISMS in support of cyber insurance” ) plus a revised scope (“This document provides guidelines when considering purchasing cyber-insurance as a risk treatment option to manage the impact of a cyber-incident within the organization’s information security risk management framework, as well as leveraging the organization’s ISMS when sharing relevant data and information with an insurer. This document gives guidelines for: a) considering the purchase of cyber insurance as a risk treatment option to share cyber risks; b) leveraging cyber insurance to assist in managing the impact of a cyber incident; c) sharing of data and information between the insured and an insurer to support underwriting, monitoring and claims activities associated with a cyber insurance policy; d) leveraging an ISMS when sharing relevant data and information with an insurer. This document is applicable to organizations that intend to purchase cyber insurance, regardless of type, size or sector.” ). Commentary The standard offers sage advice on the categories or types of incident-related costs that may or may not be covered. It concerns what I would call everyday [cyber] incidents, a subset of information security incidents. Incidents such as frauds, intellectual property theft and business interruption can also be covered by various kinds of insurance, and some such as loss of critical people may or may not be insurable. Whether these are included or excluded from cyber-insurance depends on the policy wording and interpretation. Insurers are well aware of their dependence on integrity and credibility, plus the ability to pay out on rare but severe events. This standard is a basis for mutual understanding, supporting full and frank discussions between cyber-insurers and their clients on the terms and conditions leading to appropriate insurance cover. Meanwhile both insurers and insured share a common interest in avoiding, preventing or mitigating all kinds of incident involving valuable yet vulnerable information (including the digitals), which is where the remaining ISO27k standards shine. Up Up Up This page last updated: 10 July 2026

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page