top of page

Search Results

125 results found with an empty search

  • ISO/IEC TR 27016 | ISO27001security

    Back Up Next ISO/IEC TR 27016 ISO/IEC TR 27016:2014 — Information technology — Security techniques — Information security management — Organisational economics (first edition) Up Abstract “ISO/IEC TR 27016:2014 provides guidelines on how an organisation can make decisions to protect information and understand the economic consequences of these decisions in the context of competing requirements for resources. ISO/IEC TR 27016:2014 is applicable to all types and sizes of organisations and provides information to enable economic decisions in information security management by top management who have responsibility for information security decisions.” [Source: ISO/IEC TR 27016:2014] Introduction There are substantial economic, financial and resourcing aspects to the management of information risks and security controls. Scope The ISO catalogue says ISO/IEC TR 27016 “provides guidelines on how an organisation can make decisions to protect information and understand the economic consequences of these decisions in the context of competing requirements for resources.” Structure Main clauses: 6: Information security economic factors - investment aspects 7: Economic objectives - asset values 8: Balancing information security economics for I nformation S ecurity M anagement - cost-benefit analysis Annex A: Identifcation of stakeholders and objectives for setting values Annex B: Economic decisions and key cost decision factors Annex C: Economic models appropriate for information security Annex D: Business cases calculation examples Status The current first edition was published in 2014 as a T echnical R eport since this was deemed a developing field of study. Evidently the field has not developed significantly (and I guess the first edition did such a good job) since work on a second edition ground to a halt due to lack of inputs from committee members. Commentary Some generic parts of the text may be more appropriate in the ISO27k overview sections of ISO/IEC 27000 . Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27566-2 | ISO27001security

    Back Up Next ISO/IEC 27566-2 ISO/IEC 27566-2 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 2: Technical approaches and guidance for implementation [Draft] Up Abstract ISO/IEC 27566 part 2 "describes different technical approaches suitable in different ecosystems for age assurance systems and guidance for their implementation.” [Source: Draft] Introduction ISO/IEC 27566 part 2 "provides technical guidance for implementing age assurance systems in a consistent and modular manner. It supports the practical application of the framework defined in Part 1 by identifying technical components, implementation approaches, and context-specific trade-offs. This enables privacy-respecting, effective, and policy-aligned age assurance across diverse digital and physical environments." [Source: P reliminary W ork I tem] Part 2 bridges the foundational concepts from part 1 to the analytical approaches in part 3 . Scope ISO/IEC 27655 part 2 “ includes guidance for considering the characteristics of various approaches and for making trade-offs when selecting approaches for different users, actors and use cases. The document describes different technical approaches suitable in different ecosystems for the implementation of age assurance systems or of age assurance components” [Source: P reliminary W ork I tem] Structure Main clauses [from the initial draft]: 5: Principles carried forward from part 1 6: Relating context of use to implementation choices 7: Major contexts of use 8: Selecting components 9: Specifying requirements for procurement 10: Documenting operational practice statements and evidence Annex A: Commonalities of age assurance methods and interaction models Annex B: Common concerns related to common sub-contexts of use Annex C: Enrolment , user account management, and wallet management Annex D: Relationship to part 3 Annex E: Examples of trade-off choices during design of age assurance systems Annex F: Examples of practice statements Status The PWI was approved in February 2025. Part 2 is at W orking D raft stage. Commentary 'Context of use' refers - I think - to the particular business situation in which some form of age assurance is needed. SInce these vary, the standard explains how to identify, determine and evaluate relevant requirements and parameters driving the design of the age assurance approach e.g. how important is assurance to verify a person's true age? It then offers guidance on how to go about satisfying the requirements by selecting and implementing appropriate age assurance methods and technologies. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27033-1 | ISO27001security

    Back Up Next ISO/IEC 27033-1 ISO/IEC 27033-1:2015 — Information technology — Security techniques — Network security — Part 1: Overview and concepts (second edition) Up Abstract ISO/IEC 27033 part 1 “provides an overview of network security and related definitions. It defines and describes the concepts associated with, and provides management guidance on, network security. (Network security applies to the security of devices, security of management activities related to the devices, applications/services, and end-users, in addition to security of the information being transferred across the communication links.) ... Overall it provides an overview of this International Standard and a 'road map' to all other parts.” [Source: ISO/IEC 27033-1:2015] Introduction Part 1 revised and replaced ISO/IEC 18028 part 1. It provides: A roadmap and overview of the concepts and principles underpinning the remaining parts of ISO/IEC 27033. A glossary of information security terms specific to networking. Guidance on a structured process to identify and analyse network security risks and hence define network security control requirements, including those mandated by relevant information security policies. An overview of the controls supporting network technical security architectures and related technical controls, as well as non-technical controls plus other technical controls that are not solely related to network security (thus linking to ISO/IEC 27001 , ISO/IEC 27002 and ISO/IEC 27005 plus other ISO27k standards as they are released). Scope Extends the security management guidelines provided in ISO/IEC TR 13335 and ISO/IEC 27002 etc . by detailing the specific operations and mechanisms needed to implement network security controls in a wider range of network environments, providing a bridge between general information security management issues and the specifics of implementing largely technical network security controls (e.g . firewalls, IDS/IPS, message integrity controls etc .) Structure Main clauses: 6: Overview 7: Identifying risks and preparing to identify security controls 8: Supporting controls 9: Guidelines for the definition and implementation of network security 10: Reference network scenarios - risks, design techniques and control issues 11: 'Technology ' topics - risks, design techniques and control issues 12: Develop and test security solution 13: Operate security solution 14: Monitor and review solution implementation Annex A: Cross-reference between ISO/IEC 27001 Annex A and ISO/IEC 27002 network security-related controls and ISO/IEC 27033-1 Annex B: Example template for a SecOPs document Status ISO/IEC 27033-1 revised and replaced ISO/IEC 18028-1, which in turn superceded ISO/IEC TR 13335-5. The first edition was published in 2009 . The current second edition was published in 2015 and confirmed unchanged in 2021. An extended scope for the ISO/IEC 27033 network security standards is under consideration to catch up with recent and emerging technologies such as cloud computing, zero trust, IoT and AI. Consequently the initial routine standards revision project was stopped and restarted at P reliminary W ork I nstruction stage in 2025. Commentary Part 1 mentions requirements such as non-repudiation and reliability in addition to the classical CIA triad (confidentiality, integrity and availability). It provides a reasonably technical overview of network security despite barely any reference to the OSI or TCP/IP network stacks! At present, the ISO/IEC 27033 standards are largely (entirely?) concerned with digital data networks, but there are other kinds of networks - such as business networks, social networks, professional networks, criminal networks and socio-political/cultural networks - all with differing risks and security concerns. So, should the ISO/IEC 27033 set be extended to cover those too? If so, how? It is not exactly obvious what kinds of guidance might usefully be offered in these other areas - in fact, formally speaking, it is not even entirely clear what ‘networks’ are. Anyway, that’s something to bear in mind. SC 27, meanwhile, tends to stick to the knitting i.e. IT/cyber security, in accordance with its defined scope. Furthermore, I feel the information risk and security aspects of industrial shop-floor O perational T echnology networks are inadequately covered by current ISO/IEC 27033 standards, a significant omission. The networking protocols, risks and controls vary, while the gradual convergence of IT and OT is bound to affect network security in both domains. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TS 27103 | ISO27001security

    Back Up Next ISO/IEC TS 27103 ISO/IEC TS 27103:2026 — Cybersecurity — Guidance on using ISO and IEC standards in a cybersecurity framework (first edition*) Up Abstract ISO/IEC TS 27103 "provides guidance on how to leverage existing ISO and IEC standards in a cybersecurity framework.” [Source: ISO/IEC TS 27103:20 26] Introduction "The concepts behind information security can be used to assess and manage cybersecurity risks. The key question is how to manage cybersecurity risk in a comprehensive and structured manner, and ensure that processes, governance and controls are addressed. This can be done through a management systems approach. An Information Security Management system (ISMS) as described in ISO/IEC 27001 is a well proven way for any organization to implement a risk-based approach to cybersecurity. [ISO/IEC TS 27103] demonstrates how a cybersecurity framework can utilize current information security standards to achieve a well-controlled approach to cybersecurity management." [Source: ISO/IEC TS 27103:2026] Scope The standard offers guidance on using existing ISO and IEC standards (not just ISO27k ) in a "risk-based, prioritized, flexible, outcome-focused, and communications-enabling framework for cybersecurity". The 'cybersecurity framework and programme' is described as a set of five 'activities' relating to the 'target state for cybersecurity' (in other word, objectives), applying the conventional systematic ISO27k approach to the management of 'cybersecurity risk': Describe the organization’s current cybersecurity status; Describe the organization’s target state for cybersecurity; Identify and prioritize opportunities for improvement; Assess progress toward the target state; and Communicate among internal and external stakeholders about cybersecurity risk Somewhat confusingly, the 'framework and programme' also revolves around five 'functions' relating to the incident timescale - basically NIST's C yber S ecurity F ramework : Identify - business context, resources and risks relating to critical [business] functions; Protect - safeguard delivery of critical infrastructure services; Detect - activities to identify cybersecurity events, promptly; Respond - react to and contain identified events; Recover - resilience and restoration of impaired capabilities or services. The 'functions' are further divided into 'categories' and 'subcategories' which are cross-referenced to relevant clauses in ISO27k and other standards. Structure Main clauses: 5: Background - risk-based approach, stakeholders, framework and programme 6: Concepts - overview, framework functions Annex A: Sub-categories - identify, protect, detect, respond, recover Annex B: Three principles of the cybersecurity [plus ten essentials] for top management - an alternative to NIST's CSF, cross-referenced to ISO27k standards Status * This standard was initially published as a T echnical R eport in 2018 and confirmed unchanged in 2022 . It was updated, becoming the current first edition T echnical S pecification in 2026 . Commentary See also ISO/IEC TS 27110 . In ISO-land, a T echnical S pecification is a standard for an immature or developing technical subject. In theory, that means it should be formally reviewed within three years, becoming an I nternational S tandard if there is consensus ... otherwise continuing unchanged or being withdrawn. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TS 27560 | ISO27001security

    Back Up Next ISO/IEC TS 27560 ISO/IEC TS 27560:2023 — Privacy technologies — Consent record information structure (first edition) Up Abstract ISO/IEC TS 27560 "specifies an interoperable, open and extensible information structure for recording PII principals' consent to PII processing. [ISO/IEC TS 27560] provides requirements and recommendations on the use of consent receipts and consent records associated with a PII principal's PII processing consent, aiming to support the: provision of a record of the consent to the PII principal; exchange of consent information between information systems; management of the life cycle of the recorded consent.” [Source: ISO/IEC TS 27560:2023] Introduction This T echnical S pecification specifies an interoperable, open and extensible information structure for recording and potentially sharing PII Principals' (data subjects') consent to data processing. Scope In addition to the specification, the standard provides requirements and recommendations on the use of consent receipts and consent records associated with a PII Principal’s data processing consent to support the: Provision of a record of the consent to the PII Principal; Exchange of consent information between information systems; and Management of the lifecycle of the recorded consent. The standard does not specify an exchange protocol for receipts and records, nor an exact data structure for such exchanges. Structure Main clauses: 5: Overview of consent records and consent receipts 6: Elements of a consent record and consent receipt Annex A: Examples of consent records and receipts Annex B: Example of consent record life cycle Annex C: Performance and efficiency considerations Annex D: Consent record encoding structure Annex E: Security of consent records and receipts Annex F: Signals as controls communicating PII principal's preferences and decisions Annex G: Guidance on the application of consent receipts in the context of P rivacy I nformation M anagement S ystems Annex H: Mapping to ISO/IEC 29184 Status The first edition was published as a T echnical S pecification in 2023 . ISO made the downloadable standard free of charge in 2025 to encourage uptake and so promote the sharing of privacy consents. See https://www.iso.org/standard/80392.html A revision project is ongoing with an expanded scope to encompass the former ISO/IEC TS 27569 project (which has presumably been cancelled). The second edition is at 2nd C ommittee D raft stage with a new title: "Structure of personally identifiable information (PII) processing records.", revised scope and updated structure. It looks set to become a full I nternational S tandard rather than a T echnical S pecification. Commentary If only ISO would release all the ISO27k infosec standards free of charge, encouraging everyone to improve security, privacy and resilience for all! Nod if you agree. Better still, suggest it to your national body ... Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27031 | ISO27001security

    Back Up Next ISO/IEC 27031 ISO/IEC 27031:2025 — Cybersecurity — Information and communication technology readiness for business continuity (second edition) Up Abstract “ISO/IEC 27031 provides guidance on ensuring that information and communication technology (ICT) is prepared to support business continuity. It outlines a framework for ICT readiness that aligns with broader business continuity objectives, helping organizations to prevent, respond to and recover from ICT-related disruptions that could impact critical operations. In today’s digital world, organizations rely heavily on ICT systems to operate, deliver services and maintain trust with stakeholders. Disruptions to these systems — from cyberattacks to system failures — can have severe consequences. ISO/IEC 27031 helps organizations build ICT resilience by integrating readiness planning into business continuity and information security practices. It ensures that ICT services can be restored within agreed timeframes, protecting operations, reputation and customer trust. This readiness is not only about internal systems but also extends to dependencies on third-party services such as cloud providers. Benefits: Supports uninterrupted business operations during ICT disruptions Strengthens alignment between ICT, security and continuity strategies Reduces recovery time and data loss after incidents Enhances organisational resilience and stakeholder confidence Integrates smoothly with ISO/IEC 27001 and ISO 22301 practices” [Source: ISO.org summary page ] Introduction ISO/IEC 27031 provides guidance on the concepts and principles behind the role of I nformation and C ommunication T echnology in ensuring business continuity. The standard: Suggests a structure or framework (a coherent set or suite of methods and processes) for any organisation – private, governmental, and non-governmental; Identifies and specifies all relevant aspects including performance criteria, design, and implementation details, for improving ICT readiness as part of the organisation’s ISMS, helping to ensure business continuity; Enables an organisation to measure its ICT continuity, security and hence readiness to survive a disaster in a consistent and recognized manner. Scope The standard encompasses all events and incidents (not just information security related) that could have an impact on ICT infrastructure and systems. It therefore extends the practices of information security incident handling and management, ICT readiness planning and services. I CT R eadiness for B usiness C ontinuity [a general term for the processes described in the standard] supports B usiness C ontinuity M anagement “by ensuring that the ICT services are as resilient as appropriate and can be recovered to pre-determined levels within timescales required and agreed by the organisation.” ICT readiness is important for business continuity because ICT is prevalent and vital: many organisations’ critical business processes (including those involved in managing incidents plus the related business continuity, disaster and emergency responses) are highly dependent on ICT. Therefore, BCM would be incomplete without adequately considering the need to protect availability and continuity of the ICT. ICT readiness encompasses: Preparing the organisation’s ICT (i.e. the IT infrastructure, operations and applications), plus the associated processes and people, against unforeseeable events that could change the risk environment and impact ICT and business continuity; Leveraging and streamlining resources among business continuity, disaster recovery, emergency response and ICT security incident response and management activities. ICT readiness should of course reduce the impact (meaning the extent, duration and/or consequences) of information security incidents on the organisation. The standard incorporates the cyclical P lan-D o-C heck-A ct Deming-style approach, extending the conventional business continuity planning process to take greater account of ICT. It incorporates ‘failure scenario assessment methods’ such as F ailure M ode and E ffects A nalysis, with a focus on identifying ‘triggering events’ that could precipitate more or less serious incidents. The SC 27 team responsible for ISO/IEC 27031 liaised with ISO Technical Committee 233 on business continuity, to ensure alignment and avoid overlap or conflict. Structure Main clauses: 6: Integration of IRBC into BCM 7: Business expectations for IRBC 8: Defining prerequisites for IRBC 9: Determining IRBC strategies 10: Determining the ICT continuity plan 11: Testing, exercise, and auditing 12: Final MBCO 13: Top management responsibilities regarding evaluating the IRBC Annex A: Comparing RTO and RPO to business objectives for ICT recovery Annex B: Risk reporting for FMEA Status The first edition was published in 2011 . The revision project ran off the rails and was cancelled in 2020, then magically rebooted. The standard was revised to cover the need for ICT support for business continuity arising from both deliberate and accidental incidents. The current second edition was published in 2025 . Commentary The value of this standard is unclear, given that ISO 22301 does such a good job in this general area while ISO/IEC 24762 covers ICT D isaster R ecovery specifically. This standard could usefully be extended beyond the ICT domain since: The ISO27k standards concern risk and security to information, not just “ICT” (a clumsy and unnecessary amplification of good old “IT” which in common usage has included comms for, oh at least 50 years); O perational T echnology (such as I ndustrial C ontrol S ystems running manufacturing plant, and assorted facilities management systems providing power, cooling etc .) is not mentioned, not even once - neither included nor excluded, just completely ignored; Information in forms or formats other than computer data can be just as important for business continuity, just as valuable and just as much at risk. For example, the loss of a critical knowledge worker, perhaps even an entire high-perfoming team of professionals, can devastate the operational capability of any department. Think September 11th, or COVID, or defection to/poaching by a competitor or startup. However, at present, the standard remains entirely ICT-focused, tech-centric. Furthermore, to avoid any hint of overlap or conflict with the excellent ISO 22300 -series standards, ISO/IEC 27031 does not replace a B usiness C ontinuity M anagement S ystem. That said, the standard orbits around “IRBC” (I CT R eadiness for B usiness C ontinuity) ... which is essentially a systematic way to manage the IT elements of business continuity, supplementing the BCMS as a whole. Although the issued standard mentions ICT resilience to - as well as recovery from - disastrous situations, the coverage on resilience (the ability for critical processes and systems to withstand as well as recover from serious incidents) is limited - another potential improvement opportunity here. It is similarly light on contingency . Contingency planning involves developing the organisation’s flexibility, capability, resources and dogged determination to cope with whatever situations actually eventuate, preparing for the uncertainties and challenges ahead. What will actually happen following an incident is contingent on the situation that occurs, its significance (reflecting its scale, nature, timing, implications for the business etc .) and the resources available (surviving!) at that point. The current standard only refers once to ‘contingency’, as a convoluted and ineptly-phrased note to the definition of [ICT] readiness. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27556 | ISO27001security

    Back Up Next ISO/IEC 27556 ISO/IEC 27556:2022 — Information security, cybersecurity and privacy protection — User-centric privacy preferences management framework (first edition) Up Abstract ISO/IEC 27556 "provides a user-centric framework for handling personally identifiable information (PII), based on privacy preferences.” [Source: ISO/IEC 27556:2022] Introduction The standard lays out a “user-centric framework” (an architecture) to handle personal information in a controlled manner in accordance with the privacy-by-design and other requirements of applicable privacy laws and regulations. The standard outlines a mechanism for organisations handling personal data to comply with data subjects’ privacy requirements, even as those organisations share and collaborate on processing the data. Scope The standard describes a generic high-level system architecture without specifying the content and format of privacy preference information. The architecture, in turn, informs the design and implementation of IT systems handling personal information and communicating it between organisations, while managing the privacy preferences of data subjects (known as ‘PII Principals’ in the standard i.e. the people whose personal information is being handled). The standard expands upon ISO/IEC 29100’s “Privacy framework ”. Structure Main clauses: 5: User-centric framework for handling PII 6: Requirements and recommendations for the P rivacy P reference M anager (defined as “component providing a capability allowing PII principals to express privacy preferences and a capability to monitor PII processing according to these privacy preferences” - normally an IT system component, not a person) 7: Further considerations for the PPM in a P rivacy I nformation M anagement S ystem Annex A: Use cases of PII handling based on privacy preferences Annex B: Identifying an actor serving as a component for each example service Annex C: Guidance on configuration of privacy preferences management Annex D: Supporting the design of a privacy preference management Status The current first edition was published in 2022 . Commentary I appreciate the intent to standardise the handling and management of users’ privacy consents, perhaps allowing the preferences to be shared among systems. However, given strong commercial incentives for social media and related systems and companies to exploit every scrap of personal information they can obtain, it may take even stronger pressure from regulators and legislators on behalf of private individuals to see this widely adopted in practice. So, watch this space. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27035-2 | ISO27001security

    Back Up Next ISO/IEC 27035-2 ISO/IEC 27035-2:2023 — Information technology — Information security incident management — Part 2: Guidelines to plan and prepare for incident response (second edition) Up Abstract ISO/IEC 27035 part 2 “provides guidelines to plan and prepare for incident response and to learn lessons from incident response. The guidelines are based on the plan and prepare and learn lessons phases of the information security incident management phases model presented in [part 1 clauses] 5.2 and 5.6 ...” [Source: ISO/IEC 27035-2:2023 ] Introduction Part 2 concerns assurance that the organisation is - in fact - ready to respond appropriately to information security incidents that may yet occur. Scope Part 2 covers the Plan and prepare and Learn lessons phases of the process laid out in part 1 . Structure Main clauses: 4: Information security incident management policy 5: Updating of information security policies 6: Creating information security incident management plan 7: Establishing an incident management capability 8: Establishing internal and external relationships 9: Defining technical and other support 10: Creating information security incident awareness and training 11: Testing the information security incident management plan 12: Learn lessons ... plus annexes with example forms, incident categorization approaches, and notes on ‘legal and regulatory requirements’ (mostly privacy). Status The first edition of part 2 was published in 2016 . Having been revised for ISO/IEC 27002:2022 and with a new clause 8, the current second edition was published in 2023 . Commentary This part of ISO/IEC 27035 addresses the rhetorical question “Are we ready to respond to an incident?”. It promotes deliberately learning from incidents [of all sorts and scales, including exercises] to improve things for the future. This extends the focus beyond dealing with incidents into broader change management, governance and strategic aspects. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27017 | ISO27001security

    Back Up Next ISO/IEC 27017 ISO/IEC 27017:2015 / ITU-T X.1631 — Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services (first edition) Up Abstract “ISO/IEC 27017:2015 gives guidelines for information security controls applicable to the provision and use of cloud services by providing: additional implementation guidance for relevant controls specified in ISO/IEC 27002; additional controls with implementation guidance that specifically relate to cloud services. This Recommendation | International Standard provides controls and implementation guidance for both cloud service providers and cloud service customers.” [Source: ISO/IEC 27017:2015/ITU-T X.1631] Introduction This standard provides guidance on the information security aspects of cloud computing, recommending and assisting with the implementation of cloud-specific information security controls supplementing the guidance in ISO/IEC 27002:2013 and other ISO27k standards . Scope The 'code of practice' provides additional information security controls implementation advice beyond that provided in ISO/IEC 27002:2013 , in the context of cloud computing. Structure The standard advises both cloud service customers and cloud service providers, with the primary guidance laid out side-by-side in each clause, mirroring the structure of ISO/IEC 27002:2013 Status The current first edition was published in 2015 . Having been developed jointly by ISO/IEC and ITU-T, the standard is dual-numbered ISO/IEC 27017 and ITU-T X.1631 with identical content. Work on a second edition started in 2022. It is being updated to “capture a full set of guidance for information security controls applicable to cloud services, both from the third [2022] edition of ISO/IEC 27002 and any additional controls specific related specifically to cloud services.” ISO/IEC SC 27 and SC 38, ITU-T SG17 and the C loud S ecurity A lliance are collaborating on the revision, requiring careful scheduling to coordinate several parallel activities. Substantial changes are coming in the second edition of this standard with a complete reorganisation of the controls as per ISO/IEC 27002:2022 . The title will become “Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services ”. It has passed a vote at F inal D raft I nternational S tandard stage, with several editorial comments that should be readily addressed. It remains on-track to for publication this year. Commentary In my opinion, ISO/IEC 27017 takes an unrealistically simplistic view of cloud service provider and customer relationships as individual one-to-one interactions. In reality, cloud services are often provided by multiple suppliers to multiple clients in different organisations, and nothing remains static for long. In practice, inter-organisational business relationships often extend through complex cloud supply chains or supply networks, with multiple parties involved in collaborating to assemble, deliver and manage cloud services (e.g . network, data centre, physical servers, virtual servers, operating systems, database management systems and other layered software, applications, and all the associated services). Consequently, there are numerous supplier-customer relationship risks to manage, such as organisational interdependence, contracting and subcontracting, complexity, dynamics and compliance. There are risk visibility and trust issues, resourcing challenges, commercial angles, technological challenges and more to contend with. Cloud-related information risks are cloudy! Risk treatments for cloud and other information risks may include risk sharing, avoidance and acceptance - not just risk mitigation using security controls. Neither this standard nor ISO/IEC 27002 pay much attention to risk treatments other than mitigation using security controls. Particularly for small or immature organisations, cloud services providing email, file storage and office apps etc . may be treated as mere commodities, procured without adequate consideration of information risk, security, privacy etc . However, some cloud services may be critical for core business, and cloud generally increases the organisation’s attack surface and vulnerabilities. [This issue may be more relevant to ISO/IEC 27005 and ISO/IEC 27036 .] Cloud services proved their value for resilience and flexible working through COVID. There are general principles and lessons here that can help organisations be better prepared to cope with future widespread/global challenges such as further pandemics, wars, Internet connectivity issues etc. Our challenge now is to draw them out, consider and embed them where appropriate - possibly in this standard. The standard has widespread support from ISO/IEC JTC 1/SC 27, ITU-T SG17, national standards bodies and CSA among others. However, aligning disparate perspectives and objectives while remaining within the defined scope of the current update project is tricky. SC 27 decided not to progress a separate cloud information security management system specification standard, judging that ISO/IEC 27001 is sufficient and given pressure from ISO not to proliferate Management Systems Standards ‘unnecessarily’. Therefore, SC 27 does not intend to develop a formal requirements specification standard against which to certify the security of cloud service providers specifically. Providers can however be certified against ISO/IEC 27001 , ISO/IEC 27701 and other standards in the usual way, while there are non-ISO cloud security assessment and certification, classification, benchmarking or assurance schemes such as CSA STAR . Up Up Up This page last updated: 10 July 2026

  • ISO/IEC TS 27564 | ISO27001security

    Back Up Next ISO/IEC TS 27564 ISO/IEC TS 27564:2025 — Privacy protection — Guidance on the use of models for privacy engineering [first edition] Up Abstract ISO/IEC TS 27564 "provides guidance on how to use modelling in privacy engineering. It describes categories of models that can be used, the use of modelling to support engineering, and the relationships with other references, including International Standards on privacy engineering and on modelling. It provides high-level use cases describing how models are used.” [Source: ISO/IEC TS 27564:2025 ] Introduction Modelling and other systems engineering approaches are useful when designing complex systems, such as IT systems plus their associated operating environments and processes. This standard is focused on using modelling and engineering to specify, design and embed suitable privacy arrangements/controls into complex [IT] systems that handle personal information. Determining requirements and incorporating privacy into the product lifecycle from the outset should reduce the issues that arise if privacy is neglected until later. Bolting-on privacy (or security or safety) late in the day is less than ideal (suboptimal), albeit still better than nothing. Scope Guidance on applying the M odel-B ased S ystems and S oftware E ngineering approach (as per ISO/IEC/IEEE 24641:2023 - Systems and Software engineering - Methods and tools for model-based systems and software engineering ) to design-in appropriate privacy controls for complex systems using conceptual models. Structure Main clauses: 5: Engineering with models - particularly MBSSE 6: Privacy engineering with models - more MBSSE 7: Guidance on the use of privacy models - and standards Annex A: Using models for privacy engineering - Examples Status The current first edition was published in 2025 . Commentary This standard explains the use of others such as ISO/IEC/IEEE 24641 , ISO/IEC 27555 (models for deletion of personal information), ISO/IEC 27556 (models for managing privacy preferences), ISO/IEC 27559 (models for de-identification) and ISO/IEC 27561 (POMME), for privacy engineering. The systems engineering approach involves determining and taking account of the context in which a complex system is to be used, as well as the complexities within, to develop a definitive model. The architectural model, in turn, drives a coordinated approach to the system development, with updates as things progress to keep everything aligned - in this case, aligned around privacy, specifically. It is published as a T echnical S pecification rather than a full International Standard, presumably because the subject matter is still in development. As such, it should (according to the ISO Directives ) be reviewed within just three years of the agreed “stability date” rather than the usual five years after publication. Up Up Up This page last updated: 10 July 2026

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page