top of page

Search Results

125 results found with an empty search

  • ISO/IEC 27102 | ISO27001security

    Back Up Next ISO/IEC 27102 ISO/IEC 27102:2019 — Information security management — Guidelines for cyber-insurance (first edition) Up Abstract ISO/IEC 27102 "provides guidelines when considering purchasing cyber-insurance as a risk treatment option to manage the impact of a cyber-incident within the organisation's information security risk management framework. ...” [Source: ISO/IEC 27102:2019] Introduction There is a global market for ‘cyber-insurance’, providing options for the transfer of some information/commercial risks to commercial providers. At present, the focus is primarily on sharing risk and providing compensation for the business costs and consequences arising from ‘cyber-incidents’ (such as serious privacy breaches caused by hacks and malware infections) that have not been entirely avoided, mitigated or simply accepted by the organisation. Scope This standard explains: Essential insurance concepts to information risk and security professionals; Essential cybersecurity concepts to insurance professionals; What the insurers and customers of cyber-insurance typically expect of each other; How to scope, determine, specify and procure appropriate cyber-insurance to managers, procurement and insurance sales professionals, and others involved in the negotiations and contracting process; The advantages and disadvantages, costs and benefits, constraints and opportunities in this area. Structure Main clauses: 5: Overview of cyber-insurance and cyber-insurance policy 6: Cyber-risk and insurance coverage 7: Risk assessment supporting cyber-insurance underwriting 8: Role of ISMS in support of cyber-insurance Annex A: Examples of ISMS documents for sharing Status The current first edition was published in 2019 . The second edition is at W orking D raft stage, refocusing on how cyber insurance can both support and draw upon an ISMS, and updating to reflect the current 2022 versions of ISO/IEC 27001 and 27002. A new title has been approved (“Guidelines for the use of ISMS in support of cyber insurance” ) plus a revised scope (“This document provides guidelines when considering purchasing cyber-insurance as a risk treatment option to manage the impact of a cyber-incident within the organization’s information security risk management framework, as well as leveraging the organization’s ISMS when sharing relevant data and information with an insurer. This document gives guidelines for: a) considering the purchase of cyber insurance as a risk treatment option to share cyber risks; b) leveraging cyber insurance to assist in managing the impact of a cyber incident; c) sharing of data and information between the insured and an insurer to support underwriting, monitoring and claims activities associated with a cyber insurance policy; d) leveraging an ISMS when sharing relevant data and information with an insurer. This document is applicable to organizations that intend to purchase cyber insurance, regardless of type, size or sector.” ). Commentary The standard offers sage advice on the categories or types of incident-related costs that may or may not be covered. It concerns what I would call everyday [cyber] incidents, a subset of information security incidents. Incidents such as frauds, intellectual property theft and business interruption can also be covered by various kinds of insurance, and some such as loss of critical people may or may not be insurable. Whether these are included or excluded from cyber-insurance depends on the policy wording and interpretation. Insurers are well aware of their dependence on integrity and credibility, plus the ability to pay out on rare but severe events. This standard is a basis for mutual understanding, supporting full and frank discussions between cyber-insurers and their clients on the terms and conditions leading to appropriate insurance cover. Meanwhile both insurers and insured share a common interest in avoiding, preventing or mitigating all kinds of incident involving valuable yet vulnerable information (including the digitals), which is where the remaining ISO27k standards shine. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TR 27563 | ISO27001security

    Back Up Next ISO/IEC TR 27563 ISO/IEC TR 27563:2023 — Security and privacy in artificial intelligence use cases — Best practices (first edition) Up Abstract ISO/IEC TR 27563 "outlines best practices on assessing security and privacy in artificial intelligence use cases, covering in particular those published in ISO/IEC TR 24030. The following aspects are addressed: an overall assessment of security and privacy on the AI system of interest; security and privacy concerns; security and privacy risks; security and privacy controls; security and privacy assurance; and security and privacy plans. Security and privacy are treated separately as the analysis of security and the analysis of privacy can differ.” [Source: ISO/IEC TR 27563:2023 ] Introduction This T echnical R eport analyses and elaborates on the information security and privacy aspects of the 132 use cases for A rtificial I ntelligence/M achine L earning systems published in ISO/IEC TR 24030:2021 “Information technology - Artificial Intelligence (AI) - use cases”, and provides four additional use cases developed specifically for this TR. Scope The standard offers information security and privacy best practice guidance following analysis of ISO/IEC 24030 ’s use cases. Structure Main clauses: 5: Analysis of security and privacy 6: Templates for analysis 7: Supporting information Annex A: Additional use cases The information security and privacy implications for related groups of AI/ML use cases have been systematically analysed. The results are summarised in bar charts, followed by tables elaborating on the analyses in a standard format. Status The current first edition was published in 2023 . Commentary Cue tumbleweed ... Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TS 27570 | ISO27001security

    Back Up Next ISO/IEC TS 27570 ISO/IEC TS 27570:2021 — Privacy protection — Privacy guidelines for smart cities (first edition) Up Abstract ISO/IEC TS 27570 "takes a multiple agency as well as a citizen-centric viewpoint. It provides guidance on: smart city ecosystem privacy protection; how standards can be used at a global level and at an organisational level for the benefit of citizens; and processes for smart city ecosystem privacy protection. ...” [Source: ISO/IEC TS 27570:2021] Introduction Smart cities’ are emerging from the confluence of public wireless networks, mobile/portable devices, the I nternet o f T hings (both industrial and consumer), automation, cloud computing, smart devices with advanced automation and artificial intelligence/machine learning, big data and more. As disparate ICT system are increasingly and dynamically communicating within our cities, both opportunities and risks are opening up for individuals plus the commercial and governmental agencies providing various services (such as communications, energy, transportation, healthcare and law enforcement). Scope Although the guideline briefly mentions information security aspects such as safety and resilience, the guideline specifically concerns privacy in the context of smart cities including ‘smart city ecosystem privacy protection’. Rhetorical questions include: To what extent is it appropriate for individuals to be identified, tracked and monitored through their ICT devices and digital interactions as they go about their business in the city? Since privacy requirements and expectations vary between the authorities, businesses and individuals, how should those tensions be managed? Even though the collection, processing and disclosure of personal data may be restricted on privacy grounds, what (if anything) can/should be done to restrict correlation and inference being used as large quantities of information become available for sharing and analysis? Is it even feasible to support (an appropriate degree of) anonymity if individuals so desire, without excluding them and denying them the advantages of interaction between smart devices? There are social/societal aspects to this, as well as the technological and personal. Given the rapid pace of change in this area, the guideline cannot fully address all the issues at this time but instead seeks to establish a reference (conceptual) framework as a basis for the development of future standards. Structure Main clauses: 5: Privacy in smart cities 6: Guidance on smart city ecosystems privacy protection 7: Guidance on standards for smart city ecosystems privacy protection 8: Guidance on processes for smart city ecosystem privacy protection Annex A: Example of ecosystem privacy plan structure Annex B: Using video cameras in smart cities The guideline provides conceptual diagrams and explanations, emphasizing other applicable standards. Status The current first edition was published as a T echnical S pecification in 2021 and confirmed unchanged in 2024. Commentary This visionary, conceptual, innovative and remarkable standard was conceived way back in 2015. The issues it covers are still barely even recognised as such at this point, at least not outside the specialism. Better to influence the thinking and direction on privacy, governance and related matters now than to complain about constraints later on when it may be too late to achieve fundamental change. If only SC 27 had taken such a proactive stance on IoT security way back when it was in its infancy! Speaking as a former biologist and current pedant, frequent use of “ecosystem” (a contraction of eco logical system ) catches my beady eye. The standard is not talking about living organisms interacting with the natural environment, but conceptual linkages between IT systems, networks, organisations and individuals in the technology context. Surely there is a more accurate and appropriate term than ‘ecosystem’ - ‘technosystem’, perhaps, contracting techno logical system ? Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TS 27115-1 | ISO27001security

    Back Up Next ISO/IEC TS 27115-1 ISO/IEC TS 27115-1 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 1: Introduction and framework overview (DRAFT) Up Abstract ISO/IEC TS 27115[-1] "provides the foundations and concepts for the cybersecurity evaluation of complex systems. Two frameworks are defined: [ISO/IEC TS 27115-2] is used to specify the cybersecurity of a complex system, including system of systems. [ISO/IEC TS 27115-3] is used to evaluate the corresponding cybersecurity solutions. The frameworks use basic architecture concepts: to enable description of reference or solution cybersecurity architectures; to support model-based, comprehensive and scalable security solutions and their evaluation; and to allow for the definition of architecture-based cybersecurity profiles and hierarchies of profiles.” [Source: adapted from ISO.org info page ] Introduction Using concepts and terms similar to the C ommon C riteria such as T arget O f E valuation and security profile, this three-part T echnical S pecification intends to explain how to: (a) Develop a security architecture (or design) for a complex system (a 'system of systems'); and (b) Evaluate a complex system against the security architecture. Scope The W orking D raft's formal definition of "complex system" as "a system or system of systems" is self-referential and unhelpful. The WD introduction refers somewhat obtusely to complex systems: The complexity of security and legislation for privacy, cybersecurity or AI (hinting, perhaps, at 'the complex system' being a computer system of some sort plus its associated security arrangements ... and perhaps the associated compliance framework/s?); 'Scaling up towards' ecosystems, or socio-technical systems (your guess is as good as mine on that one!); Systems of systems ... which apparently means subsystems or discrete systems that interact to provide services, within an environment. "System" is defined in the WD as "arrangement of parts or elements that together exhibit a stated behaviour or meaning that the individual constituents do not Note 1 to entry: A system is sometimes considered as a product or as the services it provides. Note 2 to entry: In practice, the interpretation of its meaning is frequently clarified by the use of an associative noun, e.g. aircraft system. Alternatively, the word “system” is substituted simply by a context-dependent synonym (e.g. aircraft), though this potentially obscures a system principles perspective. Note 3 to entry: A complete system includes all of the associated equipment, facilities, material, computer programs, firmware, technical documentation, services, and personnel required for operations and support to the degree necessary for self-sufficient use in its intended environment. Structure Main clauses (in a draft before being split into three parts): 5: Overview 6: Security architecture description - "concepts and elements supporting the framework for constructing a security architecture description" 7: Security architecture evaluation - evaluating systems against criteria declared in their security profiles 8: Architecture-based security profiles 9: Composed security profiles - compilation of security profiles from individual systems comprising system-of-systems Annex A: Architecture foundations Annex B: Guidance for elaborating a security architecture Annex C: Guidance for evaluating a security architecture Annex D: Security example for a network infrastructure Status The standard development project commenced in 2023. It is now at C ommittee D raft stage, split into three parts: ISO/IEC TS 27115-1 Information security, cybersecurity and privacy protection —Cybersecurity of system of systems — Part 1: Introduction and framework overview (due out in 2027). Scope: part 1 provides a framework to specify the cybersecurity of complex systems, including systems of systems. The framework uses basic architecture concepts to enable description of reference or solution security architectures. ISO/IEC TS 27115-2 Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 2: Security architecture evaluation (due in 2028). Scope: part 2 provides a framework to evaluate the cybersecurity of complex systems, including systems of systems, based on ISO/IEC TS 27115-1. The framework uses basic architecture concepts to support model-based, comprehensive and scalable security solutions and their evaluation. ISO/IEC TS 27115-3 Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 3: Security profiles (due in 2029). Scope: part 3 provides a framework to describe security profiles based on ISO/IEC TS 27115-1 and ISO/IEC TS 27115-2. The framework uses basic architecture concepts to enable the definition of architecture-based security profiles and composition of profiles. Commentary This is all Greek to me, patently not my area of expertise. It is theoretical or adademic rather than pragmatic. It doesn't help that the latest draft I've seen has hardly any usable references, most being replaced by "Error: Reference source not found ", while what I presume are internal references within the text to particular figures (e.g . "Figure 11) or tables are completely missing (e.g . "The security process can be iterative, as shown on step H in ,"). So no clues there either. The very notion of 'complex systems' puzzles me. Presumably it is a matter of scale, since systems are fractal in nature: any system is both composed of subunits ('subsystems') and comprises part of larger systems (infrastructures, frameworks, concepts or whatever). From the very tiniest subatomic particles to the entire universe, it's all one massive "system-of-systems" that are complex at every level due, in part, to interactions within and without each 'system'. In information security, context is [almost] everything: maybe that's what this set of three standards will address? Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27574 | ISO27001security

    Back Up Next ISO/IEC 27574 ISO/IEC 27574 Information security, cybersecurity and privacy protection— Privacy in brain computer interface (BCI) applications [DRAFT] Up Abstract [ISO/IEC 27574] "provides requirements and guidelines on privacy for brain computer interface applications. It provides privacy controls specific to brain computer interface applications to address the privacy risks based on the principles described in ISO/IEC 29100 and ISO/IEC 27701." [Source: P reliminary W ork I tem/initial draft] Introduction 'B rain-C omputer I nterface' refers to cutting-edge telepathic technologies such as brain implants allowing users to control smart prosthetic devices and receive information from sensors and systems directly back into their brains. This standards development project under ISO/IEC JTC 1/SC 27/WG 5 is focused on the privacy aspects of such intimate biotech connections, for example the potential for adversaries to monitor/intercept and exploit sensitive personal datacommunications. Scope Judging by the proposal, it appears the project is addressing: Privacy aspects of the intimate B rain-C omputer I nterface, rather than broader information and cyber security aspects. BCI applications i.e. the software elements of 'systems' using BCI, as opposed to, say, the hardware and procedural aspects, or indeed the medical element and biotech in general. That's not to say those other areas won't even be mentioned, and it is very early days for this project so changes are entirely possible. Structure Main clauses [from the initial draft]: 5: Classification of B rain-C omputer I nterface 6: Processing of neuro data in BCI applications 7: Privacy risk management Annex A: Typical applications (use cases ) of BCI Annex B: Threat modelling Status ISO/IEC JTC 1/SC 27/WG 5 agreed to develop this standard in December 2025. The standard's development project timeline allows roughly: 1 year for drafting; 1 year for formal committee comments, revision and approval; 1 year for finalisation ... culminating in publication at the end of 2028. Commentary Addressing privacy at the early stages of such technological developments demonstrates the principle of 'security by design', particularly if the project is able to offer constructive guidance to this nascent field on how to treat the associated information risks (ideally, not just privacy risks!). Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27034-2 | ISO27001security

    Back Up Next ISO/IEC 27034-2 ISO/IEC 27034-2:2015 — Information technology — Security techniques — Application security — Part 2: organisation normative framework (first edition) Up Abstract ISO/IEC 27034-2 “provides a detailed description of the Organization Normative Framework and provides guidance to organizations for its implementation.” [Source: ISO/IEC 27034-2:2015] Introduction Part 2 explains the structure, relationships and interdependencies between processes in the O rganisation N ormative F ramework - a suite of application security-related policies, procedures, roles and tools. Scope Part 2 provides guidance on designing, implementing, operating and auditing the ONF. Structure Main clauses: 5: O rganization N ormative F ramework Annex A: Aligning the ONF and ASMP with ISO/IEC 15288 and ISO/IEC 12207 through ISO/IEC 15026-4 Annex B: ONF implementation example : implementing ISO/IEC 27034 Application Security and its ONF in an existing organization Status The current first edition of part 2 was published in 2015 and confirmed unchanged in 2021. Commentary The highly structured ONF approach approach is formal and bureaucratic e.g. a committee is needed to oversee the ONF, hence it seems most likely to suit mature organisations who already have or need a highly structured way of securing the applications they develop. It is light-years away from vibe coding. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27036-4 | ISO27001security

    Back Up Next ISO/IEC 27036-4 ISO/IEC 27036–4:2016 — Information security — Security techniques — Information security for supplier relationships — Part 4: Guidelines for security of cloud services (first edition) Up Abstract ISO/IEC 27036 part 4 “provides cloud service customers and cloud service providers with guidance on (a) gaining visibility into the information security risks associated with the use of cloud services and managing those risks effectively, and (b) responding to risks specific to the acquisition or provision of cloud services that can have an information security impact on organizations using these services. [Part 4] does not include business continuity management/resiliency issues involved with the cloud service. ISO/IEC 27031 addresses business continuity. [Part 4] does not provide guidance on how a cloud service provider should implement, manage and operate information security. Guidance on those can be found in ISO/IEC 27002 and ISO/IEC 27017. The scope of [part 4] is to define guidelines supporting the implementation of information security management for the use of cloud services” [Source: ISO/IEC 27036-4:2016 ] Introduction There are numerous information risks involved in the supply of cloud computing services: this standard encourages suppliers and customers to identify and address them, collaboratively in some cases. Scope Part 4 guides the suppliers and customers of cloud services on information security management for cloud services. Structure Main clauses: 5: Key cloud concepts and security threats and risks 6: Information security controls in cloud service acquisition lifecycle 7: Information security controls in cloud service providers Annex A: Information security standards for cloud providers Annex B: Mapping to ISO/IEC 27017 controls Status The current first edition of part 4 was published in 2016 and confirmed unchanged in 2022. Commentary Part 4 explicitly describes the information risks that it addresses. Full marks! Various security controls are recommended to mitigate unacceptable risks so, in order for an organisation to choose appropriate controls, it helps to know what those risks are. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27557 | ISO27001security

    Back Up Next ISO/IEC 27557 ISO/IEC 27557:2022 — Information technology — Information security, cybersecurity and privacy protection — Application of ISO 31000:2018 for organizational privacy risk management (first edition) Up Abstract ISO/IEC 27557"provides guidelines for organizational privacy risk management, extended from ISO 31000:2018. [ISO/IEC 27557] provides guidance to organizations for integrating risks related to the processing of personally identifiable information (PII) as part of an organizational privacy risk management programme. It distinguishes between the impact that processing PII can have on an individual with consequences for organizations (e.g. reputational damage). It also provides guidance for incorporating the following into the overall organizational risk assessment: organizational consequences of adverse privacy impacts on individuals; and organizational consequences of privacy events that damage the organization (e.g. by harming its reputation) without causing any adverse privacy impacts to individuals. [ISO/IEC 27557] assists in the implementation of a risk-based privacy program which can be integrated in the overall risk management of the organization.” [Source: ISO/IEC 27557:2022] Introduction This standard advises on managing privacy risks (risks relating to or arising from the processing of personal information) that could impact the organisation and/or individuals (data subjects) as an integral part of the organisation’s overall risk management . It supports the requirement for risk management as specified in management systems such as ISO/IEC 27001 (ISMS) and ISO/IEC 27701 (PIMS), plus risk management standards - particularly ISO 31000 of course plus ISO/IEC 29134 and ISO/IEC 27005 . The standard distinguishes information risks (with the potential to harm the organisation directly) from privacy risks (with the potential to harm individuals directly and the organisation indirectly), emphasizing difference in the respective risk management activities. Having said that, there are clearly significant overlaps: ‘Personal information’ is simply a type or category of information, subject to threats to its confidentiality, integrity and availability like all other types of information; Many of the vulnerabilities that could lead to privacy incidents are also information security vulnerabilities; Many privacy-related controls are information security controls e.g. identification and authentication, access controls, incident management, compliance enforcement and reinforcement, assurance and accountability; Serious privacy breaches can materially harm the organisation’s reputation and brands, damaging business relationships and prospects, while also increasing its costs through investigation and response activities, noncompliance penalties and additional investment to improve controls and prevent recurrence; Serious information security incidents may incidentally compromise personal information as a side-effect, and/or may harm business activities that involve personal information (e.g. if the entire IT network is out of action due to ransomware or a physical disaster, the organisation may be unable to process both business and personal information: this could have severe consequences for individuals in the case of, say, a hospital). Scope The standard advises using ISO 31000 “Risk management - Guidelines” to manage privacy risks, aiding the integration of privacy risks into the organisation’s overall risk management. Structure Main clauses: 4: Principles of organizational privacy risk management 5: Framework 6: Risk management process Annex A: PII processing identification Annex B: Example privacy events and causes Annex C: Privacy impact and consequence examples Annex D: Template showing the severity scale for privacy impacts on individuals Status The current first edition was published in 2022 . Commentary When an organisation manages privacy risks, it should be protecting both its own interests and those of data subjects, in effect acting on their behalf in a custodianship role ... which differs from the usual solely corporate perspective of information risk management. There is an ethical dimension that goes beyond the organisation’s self-preservation and exploitation of business opportunities, into the realm of acting in the best interests of the individuals whose personal information they handle, and society at large. The standard does not get into ethics, aside from one brief mention of ‘unethical differential treatment of individuals’ as a privacy impact. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27400 | ISO27001security

    Back Up Next ISO/IEC 27400 ISO/IEC 27400:2022 — Cybersecurity — IoT security and privacy — Guidelines (first edition) Up Abstract ISO/IEC 27400 "provides guidelines on risks, principles and controls for security and privacy of Internet of Things (IoT) solutions.” [Source: ISO/IEC 27400:2022] Introduction The standard provides guidance on the principles, [information] risks, and the corresponding information security and privacy controls to mitigate those risks associated with the I nternet o f T hings. Insecure things can impact security and privacy in ways that differ from more conventional IT systems (e.g. desktops, laptops and servers). Therefore, appropriate security and privacy controls are needed to mitigate unacceptable risks. Things can be considered both as discrete electronic devices, and as components in larger, more complex ‘ecosystems’ potentially including: The operating systems and applications they run, delivering various services; The network infrastructure (personal, local and wide area networks); The physical world with which they interact through sensors and actuators; The people who specify, acquire, configure, use and manage them; The organisations that design and manufacture, use/operate and manage them; Society at large since things are ‘everywhere’. Challenges and information risks in the context of IoT include: Huge variety, innovation and ubiquity with things penetrating ever deeper into our businesses, homes, vehicles and lives; Vulnerabilities in the systems, applications and networks, plus the associated processes and activities (e.g. simply compiling, let alone maintaining and using, an inventory of things is tricky and costly - as we discovered during the Y2k crisis); Threats, both deliberate (e.g. hackers and malware) and natural (e.g . adverse physical operating conditions, power cuts, static discharge, design flaws, bugs/coding errors, user accidents and ineptitude); Impacts, potentially including safety hazards and property damage as well as the usual information security and privacy incidents (e.g . data corruption, disclosure, loss); Lifecycle implications (e.g. cheap, disposable, unmanaged and/or deeply embedded things may hang around for years and are unlikely to be supported or patched, ever); Ordinary users may not have an interest in or understand the security and privacy of their things , while even IT professionals may not have the time, leaving fit-and-forget things largely unmanaged, unmonitored and unmaintained; Concerns around interoperability, interaction and dependencies between things, and with other networked devices; Individually, most things have limited functionality, accessibility (e.g. minimalist human-machine interfaces) and computing performance (e.g. little processing and storage capacity); Mobility, dynamics and complexity verging on chaos and anarchy; Applications/use cases and situations may not have been anticipated by their designers/manufacturers (e.g . when things are re-purposed, combined or customised for novel applications); Things may change hands over time, affecting the context and raising the possibility of insecure configurations and inappropriate disclosure of stored information (e.g . when casually sold-on, lost or discarded). IoT designers/manufacturers and users, both individuals and organisations, may be oblivious to the information risks and appropriate/necessary controls, hence the standard (and this website!) has a role in raising awareness and trustworthiness, driving up maturity on both the supply (vendor) and the demand (customer) sides. Scope The standard is specific to IoT, covering both information security and privacy. Structure Main clauses: 5: IoT concepts 6: Risk sources for IoT systems 7: Security and privacy controls Annex A: IoT monitoring camera sample risk scenario Status The current first edition was published in 2022 . It was proposed to change this standard into a “horizontal deliverable” spanning several ISO/IEC committees with common interests in IoT, becoming a foundational standard defining the underlying concepts or principles. [I don’t know if that was accepted.] Commentary The standard strikes me as idealistic - a stretch goal for the IoT market as a whole, a reasonable strategy for an international standard. It may get traction in the area of industrial and safety-critical IoT. As to consumer grade things, it’s hard to predict much progress on security and privacy given the cost constraints and present lack of demand for security and privacy - a classic example of the need for pragmatic standards. The standard identifies some generic ‘risk sources’ and ‘risk scenarios’ relevant to IoT, essentially a selection of examples for consideration. I have some concerns about the selection and the wording, and the lack of direct linkages between the IoT security controls recommended elsewhere in the standard and the identified risks that they are presumably intended to mitigate. However, discussing relevant [information] risks in an ISO27k standard is, I feel, a positive move in its own right. Most ISO27k standards leap directly to recommending a bunch of information security controls, barely even mentioning the information risks. This standard goes a step beyond the “Just do this:” style, albeit a small step. It’s a start, a prompt for users of the standards to identify, consider and evaluate the information risks in their own contexts. I hope the information risk-aligned approach will spread to all the ISO27k standards in due course ... although so far I have seen no hint of strategic intent expressed by SC 27 along these lines, and such a change would undoubtedly take decades. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27042 | ISO27001security

    Back Up Next ISO/IEC 27042 ISO/IEC 27042:2015 — Information technology — Security techniques — Guidelines for the analysis and interpretation of digital evidence (first edition) Up Abstract “ISO/IEC 27042:2015 provides guidance on the analysis and interpretation of digital evidence in a manner which addresses issues of continuity, validity, reproducibility, and repeatability. ...” [Source: ISO/IEC 27042:2015] Introduction The fundamental purpose of the ISO27k digital forensics standards is to promote good practice methods and processes for forensic capture and investigation of digital evidence. While individual investigators, organisations and jurisdictions may well retain certain methods, processes and controls, it is hoped that standardisation will (eventually) lead to the adoption of similar if not identical approaches internationally, making it easier to compare, combine and contrast the results of such investigations even when performed by different people or organisations and potentially across different jurisdictions. Scope As the title suggests, this standard offers guidance on the process of analysing and interpreting digital evidence, which is of course just a part of the forensics process. It lays out a generic framework encapsulating good practices in this area. Aside from the standard evidential controls (maintaining the chain of custody, scrupulous documentation etc .), the standard emphasizes the integrity of the analytical and interpretational processes such that different investigators working on the same digital evidence ought to come up with essentially the same results - or at least any differences should be traceable to choices they made along the way. Given the volume, variety and complexity of digital evidence these days, that’s quite a challenge, hence the drive for standardization, good practices, common terminology and sound, rational approaches. The standard touches on issues such as the selection and use of forensic tools, plus proficiency and competency of the investigators. Structure Main clauses: 5: Investigation 6: Analysis 7: Analytical models 8: Interpretation 9: Reporting 10: Competence 11: Proficiency Annex A: Examples of Competence and Proficiency Specifications Status The current first edition was published in 2015 and confirmed unchanged in 2021. Commentary I am puzzled why SC 27 publishes and maintains several distinct forensics standards covering different aspects of forensics, when they are in reality complementary parts of the same process: ISO/IEC 27037 concerns the initial capturing of digital evidence. ISO/IEC 27041 offers guidance on the assurance aspects of digital forensics e.g. ensuring that the appropriate methods and tools are used properly. This standard covers what happens after digital evidence has been collected i.e. its analysis and interpretation. ISO/IEC 27043 covers the broader incident investigation activities, within which forensics usually occur. ISO/IEC 27050 (in 4 parts) concerns electronic discovery ... which is pretty much what the other standards cover. British Standard BS 10008 “Evidential weight and legal admissibility of electronically stored information (ESI), Specification.” may also be of interest. I understand the decision not to integrate this content into ISO/IEC 27037 but a multi-part standard would make more sense to me personally, with an overview part 1 explaining how the jigsaw pieces fit together. The editors rejected such a proposal, claiming that it was considered and rejected when the forensics standards development projects were launched. So, sorry valued customers, it seems you will have to buy and correlate multiple standards if you choose to adopt the complete ISO27k forensics suite. Up Up Up This page last updated: 10 July 2026

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page