top of page

Search Results

125 results found with an empty search

  • ISO/IEC 27000 | ISO27001security

    Back Up Next ISO/IEC 27000 ISO/IEC 27000:2026 — Information security, cybersecurity and privacy protection — I nformation S ecurity M anagement S ystems — Overview (sixth edition) Up Abstract “ISO/IEC 27000 explains the core concepts and principles behind information security management systems , or ISMS. It provides an overview of the ISO/IEC 27000 family of standards, including ISO/IEC 27001, and clarifies how these documents relate to each other. The standard helps organizations understand the foundations of information security management before selecting, implementing or working with more specific ISMS standards.” [Source: ISO.org ) Introduction What is an I nformation S ecurity M anagement S ystem? What's the point? What is it for and what is it intended to achieve? How does it do that? What does it consist of? What is it not ? If questions of that nature puzzle you, this brief standard helps by explaining a 'management system', specifically a systematic way of managing information risks and information security controls. Scope ISO/IEC 27000 outlines the ISO27k 'family of standards': ISO/IEC 27001 - ISMS requirements ISO/IEC 27002 - information security controls ISO/IEC 27003 - ISMS guidance ISO/IEC 27004 - ISMS metrics ISO/IEC 27005 - information security risk management ISO/IEC 27006-1 - ISMS certification ISO/IEC 27007 - ISMS auditing ISO/IEC TS 27008 - information security controls assessment ISO/IEC 27010 - inter-sector and inter-organizational communications ISO/IEC 27011 - information security controls for telecommunications organizations ISO/IEC 27013 - integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 (ITIL) ISO/IEC 27014 - governance of information security ISO/IEC TR 27016 - organizational economics IISO/IEC 27017 - information security controls for cloud services ISO/IEC 27019 - information security controls for energy utilities ISO/IEC 27021 - ISMS professional competencies ISO/IEC TR 27022 - ISMS processes ISO/IEC 27028 - information security control attributes It also mentions: ISO 31000 - risk management guidelines ISO/IEC 33004 - requirements for process reference, assessment and maturity ISO/IEC 17021-1 - conformity assessment ISO/IEC 17000 - conformity assessment vocabulary and general principles ISO 19011 - management systems auditing Structure The 11-page standard has just three main clauses: 3: Terms and definitions - formally defines 12 key terms used in this standard, 7 of which are shortened definitions form other standards (without their notes) leaving 5 unique definitions. [1½ pages] 4: Concepts and principles - introduces information security, risk and security management, and management systems. [4 pages] 5: Documents* related to ISMS including ISO/IEC 27001 - succinct descriptions (just a sentence or so) of each of the standards numbered 1 to 18 above. [3 pages] * Note: within ISO/IEC 27000, the term 'documents' means ISO and ISO/IEC standards, specifically, not documents in general. The mandatory and discretionary ISMS documents noted in ISO/IEC 27001 and other ISO27k standards are not described here, although a few are mentioned (e.g. ISMS scope and risk treatment plan). Status The first edition was published in 2009 . It was updated in 2012 , 2014 , 2016, 2018 and ... wait for it ... 2026 . The previous 5th edition was released by ISO for free as an introduction and promotion of ISO27k. A request has been lodged with ISO to make the current 6th edition free as well. Until that is approved and actioned, any copies of ISO/IEC 27000:2026 found loitering on the web are probably pirated. Commentary Due to an ISO policy decision, the current 2026 sixth edition dropped previous editions' extensive glossaries of dozens of ISO27k terms, leaving just a dozen actually used in this standard. However, the official definitions remain available online in ISO's Online Browsing Platform and IEC's Electropedia . Alternatively, the Cybersecurity Hyperglossary defines well over 5,000 terms in plain English, as well as quoting thousands of formal definitions. Get ~800 pages for two-thirds the price of these 11 ! Shameless plug! Have you got yours yet? The 2026 edition includes a notable but easily-overlooked change regarding the identification of 'interested parties' (stakeholders) for an organisation's information security: "Interested parties can include not only the organization’s customers, suppliers, business partners, employees, shareholders, but also government officials and, potentially, regulators. Competitors and criminals are also interested parties. Their requirements should be especially addressed by the information security controls of the ISMS. Indeed, a purpose of such information security controls is to protect the organization from the activities of such third parties." So, an appreciation of the organisation's potential adversaries implies updating the risk identification, analysis, evaluation and treatment accordingly. ISO/IEC 27000 is quite liberal in its use of the word 'requirement' and similar terms such as 'need', 'necessary', 'objective', 'essential', 'expected'. In ISO standards such as ISO/IEC 27001 , 'requirement' generally means a statement formally defining or declaring something that is mandatory in order to claim conformity - a narrow interpretation. ISO/IEC 27000 is not exclusively concerned with mandatory requirements for conformity assessment purposes, so has a more liberal interpretation. The information security controls in ISO/IEC 27001 (annex A), '27002 , '27010 , '2 7011 , '27017 and '27019 are called “Candidate necessary information security controls ” - a curiously ambiguous turn of phrase. ‘Necessary’ here is for management to determine according to its evaluation of the organisation's information risks relative to the risk appetite. ‘Candidate’ is clearly not ‘required’ and is less than ‘suggested’, but still some readers and inept auditors may feel the controls should or perhaps must be implemented. [Spoiler alert] They don't. The summary claims that ISO/IEC 27000 "clarifies how [18 ISO27k standards] relate to each other". While a table and diagram group the 18, the interrelationships or dependencies between them are not explained, unfortunately. For example, the 'sector-specific' standards ISO/IEC 27011 , '27017 and '27019 , identify information security controls (mostly drawn from ISO/IEC 27002 ) for telecoms, cloud and power companies, respectively: the processes of identifying and evaluating information risks to determine which controls are necessary, justifying the associated investments and implementation details, monitoring and managing them to achieve, maintain and gain assurance of their adequacy (efficiency and effectiveness) are covered by several other ISO27k standards. Again, those three standards do not mandate specific information security controls, nor are they comprehensive. They are generic suggestions. Up Up Up This page last updated: 21 July 2026

  • ISO27k standards (List) | ISO27001security

    ISO27k standards List ISO/IEC 27000 Open ISO/IEC 27000:2026 — Information security, cybersecurity and privacy protection — I nformation S ecurity M anagement S ystems — Overview (sixth edition) ISO/IEC 27001 Open ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements (third edition) ISO/IEC 27002 Open ISO/IEC 27002:2022 — Information security, cybersecurity and privacy protection — Information security controls (third edition) ISO/IEC 27003 Open ISO/IEC 27003:2017 — Information technology — Security techniques — Information security management systems — Guidance (second edition) ISO/IEC 27004 Open ISO/IEC 27004:2016 — Information technology — Security techniques — Information security management ― Monitoring, measurement, analysis and evaluation (second edition) ISO/IEC 27005 Open ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks (fourth edition ) ISO/IEC 27006-1 Open ISO/IEC 27006-1:2024 — Information technology, cybersecurity and privacy protection — Requirements for bodies providing audit and certification of information security management systems — Part 1: General (fourth edition) ISO/IEC 27007 Open ISO/IEC 27007:2020 — Information security, cybersecurity and privacy protection — Guidelines for information security management systems auditing (third edition) ISO/IEC TS 27008 Open ISO/IEC TS 27008:2019 — Information technology — Security techniques — Guidelines for the assessment of information security controls (second edition) ISO/IEC 27010 Open ISO/IEC 27010:2015 — Information technology — Security techniques — Information security management for inter-sector and inter-organisational communications (second edition) ISO/IEC 27011 Open ISO/IEC 27011:2024 / ITU-T X.1051 — Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for telecommunications organizations (third edition) ISO/IEC 27013 Open ISO/IEC 27013:2021 (amended ) — Information security, cybersecurity and privacy protection — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 (third edition) ISO/IEC 27014 Open ISO/IEC 27014:2020 / ITU-T X.1054 — Information security, cybersecurity and privacy protection — Governance of information security (second edition) ISO/IEC TR 27016 Open ISO/IEC TR 27016:2014 — Information technology — Security techniques — Information security management — Organisational economics (first edition) ISO/IEC 27017 Open ISO/IEC 27017:2015 / ITU-T X.1631 — Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services (first edition) ISO/IEC 27018 Open ISO/IEC 27018:2025 — Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors (third edition) ISO/IEC 27019 Open ISO/IEC 27019:2024 — Information security, cybersecurity and privacy protection — Information security controls for the energy utility industry (second edition) ISO/IEC 27021 Open ISO/IEC 27021:2017 (amended ) — Information technology — Security techniques — Competence requirements for information security management systems professionals (first edition) ISO/IEC TS 27022 Open ISO/IEC TS 27022:2021 — Information technology — Guidance on information security management system processes (first edition) ISO/IEC TR 27024 Open ISO/IEC TR 27024 — Technical Report — Information security, cybersecurity and privacy protection — Information on government and regulatory use of information security standards [DRAFT] ISO/IEC 27028 Open ISO/IEC 27028 — Information security, cybersecurity and privacy protection — Guidance on using information security control attributes [DRAFT] ISO/IEC 27031 Open ISO/IEC 27031:2025 — Cybersecurity — Information and communication technology readiness for business continuity (second edition) ISO/IEC 27032 Open ISO/IEC 27032:2023 — Cybersecurity — Guidelines for Internet security (second edition) ISO/IEC 27033-1 Open ISO/IEC 27033-1:2015 — Information technology — Security techniques — Network security — Part 1: Overview and concepts (second edition) ISO/IEC 27033-2 Open ISO/IEC 27033-2:2012 Information technology — Security techniques — Network security — Part 2: Guidelines for the design and implementation of network security (first edition) ISO/IEC 27033-3 Open ISO/IEC 27033-3:2010 Information technology — Security techniques — Network security — Part 3: Reference networking scenarios — threats, design techniques and control issues (first edition) ISO/IEC 27033-4 Open ISO/IEC 27033-4:2014 Information technology — Security techniques — Network security — Part 4: Securing communications between networks using security gateways (first edition) ISO/IEC 27033-5 Open ISO/IEC 27033-5:2013 Information technology — Security techniques — Network security — Part 5: Securing communications across networks using Virtual Private Networks (VPNs) (first edition) ISO/IEC 27033-6 Open ISO/IEC 27033-6:2016 Information technology — Security techniques — Network security — Part 6: Securing wireless IP network access (first edition) ISO/IEC 27033-7 Open ISO/IEC 27033-7:2023 Information technology — Network security — Part 7: Guidelines for network virtualization security (first edition) ISO/IEC 27034-1 Open ISO/IEC 27034-1:2011 (corrected )— Information technology — Security techniques — Application security — Part 1: Overview and concepts (first edition) ISO/IEC 27034-2 Open ISO/IEC 27034-2:2015 — Information technology — Security techniques — Application security — Part 2: organisation normative framework (first edition) ISO/IEC 27034-3 Open ISO/IEC 27034-3:2018 — Information technology — Security techniques — Application security — Part 3: Application security management process (first edition) ISO/IEC 27034-5 Open ISO/IEC 27034-5:2017 — Information technology — Security techniques — Application security — Part 5: Protocols and application security controls data structure (first edition) ISO/IEC 27034-6 Open ISO/IEC 27034-6:2016 — Information technology — Security techniques — Application security — Part 6: Case studies (first edition) ISO/IEC 27034-7 Open ISO/IEC 27034-7:2018 — Information technology — Security techniques — Application security — Part 7: Assurance prediction framework (first edition) ISO/IEC 27035-1 Open ISO/IEC 27035-1:2023 — Information technology — Information security incident management — Part 1: Principles and process (second edition) ISO/IEC 27035-2 Open ISO/IEC 27035-2:2023 — Information technology — Information security incident management — Part 2: Guidelines to plan and prepare for incident response (second edition) ISO/IEC 27035-3 Open ISO/IEC 27035-3:2020 — Information technology — Information security incident management — Part 3: Guidelines for ICT incident response operations (first edition) ISO/IEC 27035-4 Open ISO/IEC 27035-4:2024 — Information technology — Information security incident management — Part 4: Coordination (first edition) ISO/IEC 27036-1 Open ISO/IEC 27036-1:2021 — Cybersecurity — Supplier relationships — Part 1: Overview and concepts (second edition) ISO/IEC 27036-2 Open ISO/IEC 27036-2:2022 — Cybersecurity — Supplier relationships — Part 2: Requirements (second edition) ISO/IEC 27036-3 Open ISO/IEC 27036-3:2023 — Cybersecurity — Supplier relationships — Part 3: Guidelines for hardware, software, and services supply chain security (second edition) ISO/IEC 27036-4 Open ISO/IEC 27036–4:2016 — Information security — Security techniques — Information security for supplier relationships — Part 4: Guidelines for security of cloud services (first edition) ISO/IEC 27037 Open ISO/IEC 27037:2012 — Information technology — Security techniques — Guidelines for identification, collection, acquisition and preservation of digital evidence (first edition) ISO/IEC 27038 Open ISO/IEC 27038:2014 — Information technology — Security techniques — Specification for digital redaction (first edition) ISO/IEC 27039 Open ISO/IEC 27039:2015 — Information technology — Security techniques — Selection, deployment and operations of intrusion detection and prevention systems (IDPS) (first edition) ISO/IEC 27040 Open ISO/IEC 27040:2024 — Information technology — Security techniques — Storage security (second edition) ISO/IEC 27041 Open ISO/IEC 27041:2015 — Information technology — Security techniques — Guidance on assuring suitability and adequacy of incident investigative method (first edition) ISO/IEC 27042 Open ISO/IEC 27042:2015 — Information technology — Security techniques — Guidelines for the analysis and interpretation of digital evidence (first edition) ISO/IEC 27043 Open ISO/IEC 27043:2015 — Information technology — Security techniques — Incident investigation principles and processes (first edition) ISO/IEC 27045 Open ISO/IEC 27045 — Information technology — Big data security and privacy — Guidelines for managing big data risks [DRAFT] ISO/IEC 27046 Open ISO/IEC 27046 — Information technology — Big data security and privacy — Implementation guidelines [DRAFT] ISO/IEC 27050-1 Open ISO/IEC 27050-1:2019 — Information technology — Security techniques — Electronic discovery — Part 1: Overview and concepts (second edition) ISO/IEC 27050-2 Open ISO/IEC 27050-2:2018 — Information technology — Security techniques — Electronic discovery — Part 2: Guidance for governance and management of electronic discovery (first edition) ISO/IEC 27050-4 Open ISO/IEC 27050-4:2021 — Information technology — Electronic discovery — Part 4: Technical readiness (first edition) ISO/IEC 27050-3 Open ISO/IEC 27050-3:2020 — Information technology — Security techniques — Electronic discovery — Part 3: Code of practice for electronic discovery (second edition) ISO/IEC 27070 Open ISO/IEC 27070:2021 — Information technology — Security techniques — Requirements for establishing virtualized roots of trust (first edition) ISO/IEC 27071 Open ISO/IEC 27071:2023 — Cybersecurity — Security recommendations for establishing trusted connections between devices and services (first edition) ISO/IEC 27090 Open ISO/IEC 27090 — Cybersecurity — Artificial Intelligence — Guidance for addressing security threats and compromises to artificial intelligence systems [DRAFT] ISO/IEC 27091 Open ISO/IEC 27091 — Cybersecurity and privacy — Artificial Intelligence — Privacy protection [DRAFT] ISO/IEC 27099 Open ISO/IEC 27099:2022 — Information technology — Public key infrastructure — Practices and policy framework (first edition) ISO/IEC TS 27100 Open ISO/IEC TS 27100:2020 — Information technology — Cybersecurity — Overview and concepts (first edition) ISO/IEC 27102 Open ISO/IEC 27102:2019 — Information security management — Guidelines for cyber-insurance (first edition) ISO/IEC TS 27103 Open ISO/IEC TS 27103:2026 — Cybersecurity — Guidance on using ISO and IEC standards in a cybersecurity framework (first edition*) ISO/IEC TR 27109 Open ISO/IEC TR 27109 — Information security, cybersecurity and privacy protection — Cybersecurity education and training [DRAFT] ISO/IEC TS 27110 Open ISO/IEC TS 27110:2021 — Information security, cybersecurity and privacy protection — Cybersecurity framework development guidelines (first edition) ISO/IEC TS 27115-1 Open ISO/IEC TS 27115-1 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 1: Introduction and framework overview (DRAFT) ISO/IEC TS 27115-2 Open ISO/IEC TS 27115-2 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 2: Security architecture evaluation (DRAFT) ISO/IEC TS 27115-3 Open ISO/IEC TS 27115-3 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 3: Security profiles [DRAFT] ISO/IEC TS 27116-1 Open ISO/IEC TS 27116-1 — Information security, cybersecurity and privacy protection — Framework for customised and multipurpose evaluation [DRAFT] ISO/IEC 27400 Open ISO/IEC 27400:2022 — Cybersecurity — IoT security and privacy — Guidelines (first edition) ISO/IEC 27402 Open ISO/IEC 27402:2023 — Cybersecurity — IoT security and privacy — Device baseline requirements [first edition] ISO/IEC 27403 Open ISO/IEC 27403:2024 — Cybersecurity — IoT security and privacy — Guidelines for IoT-domotics (first edition) ISO/IEC 27404 Open ISO/IEC 27404:2025 — Cybersecurity — IoT security and privacy — Cybersecurity labelling framework for consumer IoT [first edition] ISO/IEC 27503 Open ISO/IEC 27503 — Privacy and security guidelines on intelligent travel services [ P reliminary W ork I tem] ISO/IEC 27504 Open ISO/IEC 27504 — Privacy protection of user avatar and system avatar interactions in the metaverse [DRAFT] ISO/IEC TR 27550 Open ISO/IEC TR 27550:2019 — Information technology — Security techniques — Privacy engineering for system life cycle processes (first edition) ISO/IEC 27551 Open ISO/IEC 27551:2021 — Information security, cybersecurity and privacy protection — Requirements for attribute-based unlinkable entity authentication (first edition) ISO/IEC 27553-1 Open ISO/IEC 27553-1:2022 — Information security, cybersecurity and privacy protection — Security and privacy requirements for authentication using biometrics on mobile devices — Part 1: local modes (first edition) ISO/IEC 27553-2 Open ISO/IEC 27553-2:2025 — Information security, cybersecurity and privacy protection — Security and privacy requirements for authentication using biometrics on mobile devices — Part 2: remote modes (first edition) ISO/IEC 27554 Open ISO/IEC 27554:2024 — Information security, cybersecurity and privacy protection — Application of ISO 31000 for assessment of identity-related risk [first edition] ISO/IEC 27555 Open ISO/IEC 27555:2021 — Information security, cybersecurity and privacy protection — Guidelines on personally identifiable information deletion (first edition) ISO/IEC 27556 Open ISO/IEC 27556:2022 — Information security, cybersecurity and privacy protection — User-centric privacy preferences management framework (first edition) ISO/IEC 27557 Open ISO/IEC 27557:2022 — Information technology — Information security, cybersecurity and privacy protection — Application of ISO 31000:2018 for organizational privacy risk management (first edition) ISO/IEC 27559 Open ISO/IEC 27559:2022 — Information security, cybersecurity and privacy protection — Privacy-enhancing data de-identification framework (first edition) ISO/IEC TS 27560 Open ISO/IEC TS 27560:2023 — Privacy technologies — Consent record information structure (first edition) ISO/IEC 27561 Open ISO/IEC 27561:2024 — Information security, cybersecurity and privacy protection — Privacy operationalisation model and method for engineering (POMME) ( first edition) ISO/IEC 27562 Open ISO/IEC 27562:2024 — Information technology — Security techniques — Privacy guidelines for fintech services (first edition) ISO/IEC TR 27563 Open ISO/IEC TR 27563:2023 — Security and privacy in artificial intelligence use cases — Best practices (first edition) ISO/IEC TS 27564 Open ISO/IEC TS 27564:2025 — Privacy protection — Guidance on the use of models for privacy engineering [first edition] ISO/IEC 27565 Open ISO/IEC 27565:2026 — Information technology, cybersecurity and privacy protection — Guidelines on privacy preservation based on zero knowledge proofs [First edition] ISO/IEC 27566-1 Open ISO/IEC 27566-1:2025 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 1: Framework [First edition] ISO/IEC 27566-2 Open ISO/IEC 27566-2 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 2: Technical approaches and guidance for implementation [Draft] ISO/IEC 27566-3 Open ISO/IEC 27566-3 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 3: Approaches to analysis or comparison [DRAFT] ISO/IEC TS 27568 Open ISO/IEC TS 27568 — Security and privacy of digital twins [DRAFT] ISO/IEC TS 27569 Open ISO/IEC TS 27569 — Personal identifiable information (PII) processing record information structure [PROPOSAL] ISO/IEC TS 27570 Open ISO/IEC TS 27570:2021 — Privacy protection — Privacy guidelines for smart cities (first edition) ISO/IEC 27573 Open ?? ISO/IEC 27574 Open ISO/IEC 27574 Information security, cybersecurity and privacy protection— Privacy in brain computer interface (BCI) applications [DRAFT]

  • ISO27k standards info from ISO27001security

    All about the ISO/IEC 27000-series information risk and security management standards "ISO27k" refers to the ISO/IEC 27000 series standards, a set of 100 good practice guidelines for managing the risks affecting or involving information. They are listed below. "ISO/IEC" denotes the bodies that jointly developed the standards. ISO is the International Organization for Standardisation , IEC is the I nternational E lectrotechnical C ommission . Effective information risk management protects (secures) valuable information against harm whilst also permitting its use (exploitation) for business purposes. This involves systematically: Identifying risks of concern, analysing and evaluating them; Treating (avoiding, sharing, mitigating or accepting) the risks appropriately; Ensuring the risk treatments are working properly (assurance ); and Handling changes and driving continual improvement (maturity ). The standards define and comprise a ‘management system’ (governance and management arrangements) that can be adapted to suit any organisation's unique situation. Two key ISO27k standards are: ISO/IEC 27001 (I nformation S ecurity M anagement S ystem - the ISMS ); and ISO/IEC 27701 (P rivacy I nformation M anagement S ystem - the PIMS ). Other ISO27k standards expand on various aspects in more detail: ISO/IEC 27005 , for instance, elaborates on the information risk management process, while ISO/IEC 27004 offers advice on security metrics. Click the More links below for lots more information. Introduction The ISO27k standards ISO/IEC 27000 ISO/IEC 27000:2026 — Information security, cybersecurity and privacy protection — I nformation S ecurity M anagement S ystems — Overview (sixth edition) More ISO/IEC 27001 ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements (third edition) More ISO/IEC 27002 ISO/IEC 27002:2022 — Information security, cybersecurity and privacy protection — Information security controls (third edition) More ISO/IEC 27003 ISO/IEC 27003:2017 — Information technology — Security techniques — Information security management systems — Guidance (second edition) More ISO/IEC 27004 ISO/IEC 27004:2016 — Information technology — Security techniques — Information security management ― Monitoring, measurement, analysis and evaluation (second edition) More ISO/IEC 27005 ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks (fourth edition ) More ISO/IEC 27006-1 ISO/IEC 27006-1:2024 — Information technology, cybersecurity and privacy protection — Requirements for bodies providing audit and certification of information security management systems — Part 1: General (fourth edition) More ISO/IEC 27007 ISO/IEC 27007:2020 — Information security, cybersecurity and privacy protection — Guidelines for information security management systems auditing (third edition) More ISO/IEC TS 27008 ISO/IEC TS 27008:2019 — Information technology — Security techniques — Guidelines for the assessment of information security controls (second edition) More ISO/IEC 27010 ISO/IEC 27010:2015 — Information technology — Security techniques — Information security management for inter-sector and inter-organisational communications (second edition) More ISO/IEC 27011 ISO/IEC 27011:2024 / ITU-T X.1051 — Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for telecommunications organizations (third edition) More ISO/IEC 27013 ISO/IEC 27013:2021 (amended ) — Information security, cybersecurity and privacy protection — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 (third edition) More ISO/IEC 27014 ISO/IEC 27014:2020 / ITU-T X.1054 — Information security, cybersecurity and privacy protection — Governance of information security (second edition) More ISO/IEC TR 27016 ISO/IEC TR 27016:2014 — Information technology — Security techniques — Information security management — Organisational economics (first edition) More ISO/IEC 27017 ISO/IEC 27017:2015 / ITU-T X.1631 — Information technology — Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services (first edition) More ISO/IEC 27018 ISO/IEC 27018:2025 — Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors (third edition) More ISO/IEC 27019 ISO/IEC 27019:2024 — Information security, cybersecurity and privacy protection — Information security controls for the energy utility industry (second edition) More ISO/IEC 27021 ISO/IEC 27021:2017 (amended ) — Information technology — Security techniques — Competence requirements for information security management systems professionals (first edition) More ISO/IEC TS 27022 ISO/IEC TS 27022:2021 — Information technology — Guidance on information security management system processes (first edition) More ISO/IEC TR 27024 ISO/IEC TR 27024 — Technical Report — Information security, cybersecurity and privacy protection — Information on government and regulatory use of information security standards [DRAFT] More ISO/IEC 27028 ISO/IEC 27028 — Information security, cybersecurity and privacy protection — Guidance on using information security control attributes [DRAFT] More ISO/IEC 27031 ISO/IEC 27031:2025 — Cybersecurity — Information and communication technology readiness for business continuity (second edition) More ISO/IEC 27032 ISO/IEC 27032:2023 — Cybersecurity — Guidelines for Internet security (second edition) More ISO/IEC 27033-1 ISO/IEC 27033-1:2015 — Information technology — Security techniques — Network security — Part 1: Overview and concepts (second edition) More ISO/IEC 27033-2 ISO/IEC 27033-2:2012 Information technology — Security techniques — Network security — Part 2: Guidelines for the design and implementation of network security (first edition) More ISO/IEC 27033-3 ISO/IEC 27033-3:2010 Information technology — Security techniques — Network security — Part 3: Reference networking scenarios — threats, design techniques and control issues (first edition) More ISO/IEC 27033-4 ISO/IEC 27033-4:2014 Information technology — Security techniques — Network security — Part 4: Securing communications between networks using security gateways (first edition) More ISO/IEC 27033-5 ISO/IEC 27033-5:2013 Information technology — Security techniques — Network security — Part 5: Securing communications across networks using Virtual Private Networks (VPNs) (first edition) More ISO/IEC 27033-6 ISO/IEC 27033-6:2016 Information technology — Security techniques — Network security — Part 6: Securing wireless IP network access (first edition) More ISO/IEC 27033-7 ISO/IEC 27033-7:2023 Information technology — Network security — Part 7: Guidelines for network virtualization security (first edition) More ISO/IEC 27034-1 ISO/IEC 27034-1:2011 (corrected )— Information technology — Security techniques — Application security — Part 1: Overview and concepts (first edition) More ISO/IEC 27034-2 ISO/IEC 27034-2:2015 — Information technology — Security techniques — Application security — Part 2: organisation normative framework (first edition) More ISO/IEC 27034-3 ISO/IEC 27034-3:2018 — Information technology — Security techniques — Application security — Part 3: Application security management process (first edition) More ISO/IEC 27034-5 ISO/IEC 27034-5:2017 — Information technology — Security techniques — Application security — Part 5: Protocols and application security controls data structure (first edition) More ISO/IEC 27034-6 ISO/IEC 27034-6:2016 — Information technology — Security techniques — Application security — Part 6: Case studies (first edition) More ISO/IEC 27034-7 ISO/IEC 27034-7:2018 — Information technology — Security techniques — Application security — Part 7: Assurance prediction framework (first edition) More ISO/IEC 27035-1 ISO/IEC 27035-1:2023 — Information technology — Information security incident management — Part 1: Principles and process (second edition) More ISO/IEC 27035-2 ISO/IEC 27035-2:2023 — Information technology — Information security incident management — Part 2: Guidelines to plan and prepare for incident response (second edition) More ISO/IEC 27035-3 ISO/IEC 27035-3:2020 — Information technology — Information security incident management — Part 3: Guidelines for ICT incident response operations (first edition) More ISO/IEC 27035-4 ISO/IEC 27035-4:2024 — Information technology — Information security incident management — Part 4: Coordination (first edition) More ISO/IEC 27036-1 ISO/IEC 27036-1:2021 — Cybersecurity — Supplier relationships — Part 1: Overview and concepts (second edition) More ISO/IEC 27036-2 ISO/IEC 27036-2:2022 — Cybersecurity — Supplier relationships — Part 2: Requirements (second edition) More ISO/IEC 27036-3 ISO/IEC 27036-3:2023 — Cybersecurity — Supplier relationships — Part 3: Guidelines for hardware, software, and services supply chain security (second edition) More ISO/IEC 27036-4 ISO/IEC 27036–4:2016 — Information security — Security techniques — Information security for supplier relationships — Part 4: Guidelines for security of cloud services (first edition) More ISO/IEC 27037 ISO/IEC 27037:2012 — Information technology — Security techniques — Guidelines for identification, collection, acquisition and preservation of digital evidence (first edition) More ISO/IEC 27038 ISO/IEC 27038:2014 — Information technology — Security techniques — Specification for digital redaction (first edition) More ISO/IEC 27039 ISO/IEC 27039:2015 — Information technology — Security techniques — Selection, deployment and operations of intrusion detection and prevention systems (IDPS) (first edition) More ISO/IEC 27040 ISO/IEC 27040:2024 — Information technology — Security techniques — Storage security (second edition) More ISO/IEC 27041 ISO/IEC 27041:2015 — Information technology — Security techniques — Guidance on assuring suitability and adequacy of incident investigative method (first edition) More ISO/IEC 27042 ISO/IEC 27042:2015 — Information technology — Security techniques — Guidelines for the analysis and interpretation of digital evidence (first edition) More ISO/IEC 27043 ISO/IEC 27043:2015 — Information technology — Security techniques — Incident investigation principles and processes (first edition) More ISO/IEC 27045 ISO/IEC 27045 — Information technology — Big data security and privacy — Guidelines for managing big data risks [DRAFT] More ISO/IEC 27046 ISO/IEC 27046 — Information technology — Big data security and privacy — Implementation guidelines [DRAFT] More ISO/IEC 27050-1 ISO/IEC 27050-1:2019 — Information technology — Security techniques — Electronic discovery — Part 1: Overview and concepts (second edition) More ISO/IEC 27050-2 ISO/IEC 27050-2:2018 — Information technology — Security techniques — Electronic discovery — Part 2: Guidance for governance and management of electronic discovery (first edition) More ISO/IEC 27050-4 ISO/IEC 27050-4:2021 — Information technology — Electronic discovery — Part 4: Technical readiness (first edition) More ISO/IEC 27050-3 ISO/IEC 27050-3:2020 — Information technology — Security techniques — Electronic discovery — Part 3: Code of practice for electronic discovery (second edition) More ISO/IEC 27070 ISO/IEC 27070:2021 — Information technology — Security techniques — Requirements for establishing virtualized roots of trust (first edition) More ISO/IEC 27071 ISO/IEC 27071:2023 — Cybersecurity — Security recommendations for establishing trusted connections between devices and services (first edition) More ISO/IEC 27090 ISO/IEC 27090 — Cybersecurity — Artificial Intelligence — Guidance for addressing security threats and compromises to artificial intelligence systems [DRAFT] More ISO/IEC 27091 ISO/IEC 27091 — Cybersecurity and privacy — Artificial Intelligence — Privacy protection [DRAFT] More ISO/IEC 27099 ISO/IEC 27099:2022 — Information technology — Public key infrastructure — Practices and policy framework (first edition) More ISO/IEC TS 27100 ISO/IEC TS 27100:2020 — Information technology — Cybersecurity — Overview and concepts (first edition) More ISO/IEC 27102 ISO/IEC 27102:2019 — Information security management — Guidelines for cyber-insurance (first edition) More ISO/IEC TS 27103 ISO/IEC TS 27103:2026 — Cybersecurity — Guidance on using ISO and IEC standards in a cybersecurity framework (first edition*) More ISO/IEC TR 27109 ISO/IEC TR 27109 — Information security, cybersecurity and privacy protection — Cybersecurity education and training [DRAFT] More ISO/IEC TS 27110 ISO/IEC TS 27110:2021 — Information security, cybersecurity and privacy protection — Cybersecurity framework development guidelines (first edition) More ISO/IEC TS 27115-1 ISO/IEC TS 27115-1 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 1: Introduction and framework overview (DRAFT) More ISO/IEC TS 27115-2 ISO/IEC TS 27115-2 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 2: Security architecture evaluation (DRAFT) More ISO/IEC TS 27115-3 ISO/IEC TS 27115-3 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 3: Security profiles [DRAFT] More ISO/IEC TS 27116-1 ISO/IEC TS 27116-1 — Information security, cybersecurity and privacy protection — Framework for customised and multipurpose evaluation [DRAFT] More ISO/IEC 27400 ISO/IEC 27400:2022 — Cybersecurity — IoT security and privacy — Guidelines (first edition) More ISO/IEC 27402 ISO/IEC 27402:2023 — Cybersecurity — IoT security and privacy — Device baseline requirements [first edition] More ISO/IEC 27403 ISO/IEC 27403:2024 — Cybersecurity — IoT security and privacy — Guidelines for IoT-domotics (first edition) More ISO/IEC 27404 ISO/IEC 27404:2025 — Cybersecurity — IoT security and privacy — Cybersecurity labelling framework for consumer IoT [first edition] More ISO/IEC 27503 ISO/IEC 27503 — Privacy and security guidelines on intelligent travel services [ P reliminary W ork I tem] More ISO/IEC 27504 ISO/IEC 27504 — Privacy protection of user avatar and system avatar interactions in the metaverse [DRAFT] More ISO/IEC TR 27550 ISO/IEC TR 27550:2019 — Information technology — Security techniques — Privacy engineering for system life cycle processes (first edition) More ISO/IEC 27551 ISO/IEC 27551:2021 — Information security, cybersecurity and privacy protection — Requirements for attribute-based unlinkable entity authentication (first edition) More ISO/IEC 27553-1 ISO/IEC 27553-1:2022 — Information security, cybersecurity and privacy protection — Security and privacy requirements for authentication using biometrics on mobile devices — Part 1: local modes (first edition) More ISO/IEC 27553-2 ISO/IEC 27553-2:2025 — Information security, cybersecurity and privacy protection — Security and privacy requirements for authentication using biometrics on mobile devices — Part 2: remote modes (first edition) More ISO/IEC 27554 ISO/IEC 27554:2024 — Information security, cybersecurity and privacy protection — Application of ISO 31000 for assessment of identity-related risk [first edition] More ISO/IEC 27555 ISO/IEC 27555:2021 — Information security, cybersecurity and privacy protection — Guidelines on personally identifiable information deletion (first edition) More ISO/IEC 27556 ISO/IEC 27556:2022 — Information security, cybersecurity and privacy protection — User-centric privacy preferences management framework (first edition) More ISO/IEC 27557 ISO/IEC 27557:2022 — Information technology — Information security, cybersecurity and privacy protection — Application of ISO 31000:2018 for organizational privacy risk management (first edition) More ISO/IEC 27559 ISO/IEC 27559:2022 — Information security, cybersecurity and privacy protection — Privacy-enhancing data de-identification framework (first edition) More ISO/IEC TS 27560 ISO/IEC TS 27560:2023 — Privacy technologies — Consent record information structure (first edition) More ISO/IEC 27561 ISO/IEC 27561:2024 — Information security, cybersecurity and privacy protection — Privacy operationalisation model and method for engineering (POMME) ( first edition) More ISO/IEC 27562 ISO/IEC 27562:2024 — Information technology — Security techniques — Privacy guidelines for fintech services (first edition) More ISO/IEC TR 27563 ISO/IEC TR 27563:2023 — Security and privacy in artificial intelligence use cases — Best practices (first edition) More ISO/IEC TS 27564 ISO/IEC TS 27564:2025 — Privacy protection — Guidance on the use of models for privacy engineering [first edition] More ISO/IEC 27565 ISO/IEC 27565:2026 — Information technology, cybersecurity and privacy protection — Guidelines on privacy preservation based on zero knowledge proofs [First edition] More ISO/IEC 27566-1 ISO/IEC 27566-1:2025 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 1: Framework [First edition] More ISO/IEC 27566-2 ISO/IEC 27566-2 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 2: Technical approaches and guidance for implementation [Draft] More ISO/IEC 27566-3 ISO/IEC 27566-3 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 3: Approaches to analysis or comparison [DRAFT] More ISO/IEC TS 27568 ISO/IEC TS 27568 — Security and privacy of digital twins [DRAFT] More ISO/IEC TS 27569 ISO/IEC TS 27569 — Personal identifiable information (PII) processing record information structure [PROPOSAL] More ISO/IEC TS 27570 ISO/IEC TS 27570:2021 — Privacy protection — Privacy guidelines for smart cities (first edition) More ISO/IEC 27573 ?? More ISO/IEC 27574 ISO/IEC 27574 Information security, cybersecurity and privacy protection— Privacy in brain computer interface (BCI) applications [DRAFT] More ISO/IEC 27575 ?? More ISO/IEC 27701 ISO/IEC 27701:2025 — Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance (second edition) More ISO/IEC 27706 ISO/IEC 27706:2025 — Information security, cybersecurity and privacy protection — Requirements for bodies providing audit and certification of privacy information management systems (first edition) More ISO 27799 ISO 27799:2025 — Health informatics — Information security controls in health using ISO/IEC 27002 (third edition) More

  • ISO/IEC 27566-3 | ISO27001security

    Back Up Next ISO/IEC 27566-3 ISO/IEC 27566-3 — Information security, cybersecurity and privacy protection — Age assurance systems — Part 3: Approaches to analysis or comparison [DRAFT] Up Abstract ISO/IEC 27566 part 3 "establishes considerations for analysing, comparing or differentiating the characteristics of age assurance systems or components. The document includes metrics, elements and indicators of effectiveness for age assurance systems or components." [Source: C ommittee D raft] Introduction Part 3 concerns gaining assurance regarding the accuracy of age verification approaches through techniques to measure, analyse and compare approaches - for example when adult website or application designers are considering various ways to distinguish children from adult users. Scope Measuring relevant characteristics and analysing them in order to assess the suitability of various age assurance approaches. The standard does not define age thresholds or criteria to determine whether the age detection system is or is not appropriate for a given use case, but rather describes how to go about examining and analysing the system for its suitability. Structure Main clauses (so far - in the 2nd C ommittee D raft): 5: Approaches to analysis or comparison 6: Indicators of effectiveness 7: Analysis considerations 8: Characteristics and measurements for age assurance components 9: Reporting of analysis results Annex A: Document authenticity Annex B: Illustrative age assurance deployment models Annex C: Measurement of the classification accuracy for classification models using facial analysis Annex D: Sample breakdowns, liveness detecton and biometric presentation attack detection for facial age estimation methods Annex E: Example analysis report Status The standard development project launched in 2023. Part 3 is at D raft I nternational S tandard stage. It may be published towards the end of 2026 but more likely in 2027. Commentary See also ISO/IEC 27566-1 and ISO/IEC 27566-2 . Up Up Up This page last updated: 15 July 2026

  • ISO/IEC TS 27568 | ISO27001security

    Back Up Next ISO/IEC TS 27568 ISO/IEC TS 27568 — Security and privacy of digital twins [DRAFT] Up Abstract ISO/IEC TS 27568 "provides a guidance for organizations to address security and privacy risks in digital twin systems. The guidance in this document helps organizations identify security and privacy risks throughout the digital twin systems lifecycles system lifecycle, and establishes mechanisms to evaluate the consequences of such risks and treat risks them. This document is applicable to all types and sizes of organizations, including public and private companies, government entities, academia, research institutions and not-for- profit organizations, that develop or use digital twin systems." Source: ISO.org page about the draft Introduction Digital twins are essentially digital analogues, representations or realistic models of real-world situations used for various purposes. Scope This T echnical S pecification is intended to address the security and privacy implications of digital twins, supporting other digital twinning standards as the field develops at pace. Structure ?? Status The standard development project launched in 2025. Publication as a T echnical S pecification is planned for 2028. It is currently at W orking D raft stage. Commentary [Nothing to say, yet. My head is empty. I have the thousand yard stare.] Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27573 | ISO27001security

    Back Up Next ISO/IEC 27573 ?? Up Abstract ?? Introduction ?? Scope ?? Structure ?? Status ?? Commentary All I know about the standard at this early stage is its number but, hey, "I learn, I learn, I get better ... What is witnit? ". Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27575 | ISO27001security

    Back Up Next ISO/IEC 27575 ?? Up Abstract ?? Introduction ?? Scope ?? Structure ?? Status The standard development project evidently launched with a P reliminary W ork I tem in 2026. Commentary Besides the number of a PWI, "I know nothing, mister Fawlty ". Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27028 | ISO27001security

    Back Up Next ISO/IEC 27028 ISO/IEC 27028 — Information security, cybersecurity and privacy protection — Guidance on using information security control attributes [DRAFT] Up Abstract ISO/IEC 27028 "provides guidance on the use of information security control attributes. The guidance given in this document is generic and is intended to be applicable to all organizations, regardless of type, size, or nature.” [Source: ISO's page on ISO/IEC DIS 27028 ] Introduction In 2022, the third edition of ISO/IEC 27002 introduced a new structure for information security controls, based around ‘themes’ and ‘attributes’, noting that organisations may prefer to use their own attributes as well or instead. ISO/IEC 27028 will explain how to do that, in practice, suggesting a variety of attributes with which to classify or characterise, select or design information security controls in various ways for various information security and business management purposes. Scope The standard will expand upon the five control attributes in ISO/IEC 27002 i.e. Control type. Information security properties. Cybersecurity concepts. Operational capabilities. Security domains. It will provide practical guidance on how to use the specified attributes and how to develop additional attributes and attribute values where appropriate. ISO/IEC 27002 casually mentioned that this is possible but did not explain how or why. Structure Main sections: 5: Overview on [of] attribute approach 6: Additional attributes Some 16 control attributes are suggested in addition to those five from ISO/IEC 27002 , and there is advice on extending the approach to other information security controls and control attributes. Status Work started on this project in 2021. It may be published as a T echnical S pecification rather than a full I nternational S tandard since the approach is innovative and not yet proven by experience ... but we will see. The first D raft I nternational S tandard was approved by SC 27 in November 2025, with comments leading to the release of a second DIS in December. Publication is expected towards the middle or second half of 2026. Commentary There has been significant interest and support for the control attributes concept from ISO/IEC JTC 1/SC 27 . When it is finally published, I believe ISO/IEC TS 27028 will be a valuable contribution to the field, expanding on the value and utility of ISO/IEC 27002 . Meanwhile, a free guideline explains how control attributes can be used creatively within an ISO27k ISMS, or indeed any other information risk-based framework that involves mitigating unacceptable risks using appropriate information security controls. Thinking about which attributes or characteristics of controls are relevant, plus the importance of the corresponding attribute values or parameters, helps round-off the analysis and select or design appropriate controls. As usual, exploring objectives in detail generates insight that leads to a more successful outcome. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27035-4 | ISO27001security

    Back Up Next ISO/IEC 27035-4 ISO/IEC 27035-4:2024 — Information technology — Information security incident management — Part 4: Coordination (first edition) Up Abstract ISO/IEC 27035 part 4 “provides guidelines for multiple organizations handling information security incidents in a coordinated manner. It also addresses the impacts of external cooperation on the internal incident management of an individual organization and provides guidelines for an individual organization to adapt to the coordination process. Furthermore, it provides guidelines for the coordination team, if it exists, to perform coordination activities supporting the cross-organization incident response. The principles given in [ISO/IEC 27035-4] are generic and are intended to be applicable to multiple organizations to work together to handle information security incidents, regardless of their types, sizes or nature. Organizations can adjust the guidance given in [ISO/IEC 27035-4] according to their type, sizes and nature of business in relation to the information security risk situation. [ISO/IEC 27035-4] is also applicable to an individual organization that participates in partner relationships.” [Source: ISO/IEC 27035-4:2024 ] Introduction Whereas managing routine information security incidents typically involves several departments or teams within an organisation, exceptional/major incidents (such as botnet or phishing attacks) often require collaboration and coordination between the I ncident R esponse T eams of several organisations, often in different countries. In addition to those diectly affected, Internet and cloud service providers, law enforcement and maybe the security services may be involved. Scope Part 4 is about coordinating responses to major incidents with other implicated, involved or support organisations, such as cloud and network suppliers. Structure Main clauses: 4: Overview 5: Coordinated incident management process 6: Guidelines for key activities of coordinated incident management Annex A: Examples of information security incident management coordination Status The current first edition was published in 2024 . Commentary Exercises are an excellent way to plan, practice, prove and improve the coordinated interactions required in an actual incident - from the ground floor operations through the specialist and management levels to the executives in the penthouse suite, among all the participants. Stress levels relating to the ongoing incident are obviously lower in a simulation compared to reality, but stresses relating to the processes being exercised may be higher due to their unfamiliarity: better to get a grip on them now than just wing-it in an actual crisis. Modelling is another useful technique, perhaps using AI-enhanced "digital twins" to simulate the individuals, teams and organisations responding. Finally, I'll point out that suppliers of cloud, Internet, forensics, insurance and other business services have more opportunities than most to gain competence and expertise in this area as they support multiple clients through various crises, learning by doing. That's potentially a valuable and hence marketable commercial advantage. Up Up Up This page last updated: 10 July 2026

  • ISO/IEC 27004 | ISO27001security

    Back Up Next ISO/IEC 27004 ISO/IEC 27004:2016 — Information technology — Security techniques — Information security management ― Monitoring, measurement, analysis and evaluation (second edition) Up Abstract “ISO/IEC 27004:2016 provides guidelines intended to assist organisations in evaluating the information security performance and the effectiveness of an information security management system in order to fulfil the requirements of ISO/IEC 27001:2013, 9.1. It establishes: (a) the monitoring and measurement of information security performance; (b) the monitoring and measurement of the effectiveness of an information security management system (ISMS) including its processes and controls; [and] (c) the analysis and evaluation of the results of monitoring and measurement.” [Source: ISO/IEC 27004:2016] Introduction ISO/IEC 27004 concerns measurements or measures needed for information security management: these are commonly known as ‘security metrics’ in the profession (if not within ISO/IEC JTC 1/SC 27!). Scope The standard is intended to help an organisation evaluate the effectiveness and efficiency of its I nformation S ecurity M anagement S ystem, providing information necessary to manage and (where necessary) improve the ISMS systematically. It expands substantially on Clause 9.1 of ISO/IEC 27001 concerning ‘monitoring, measurement, analysis and evaluation’. Structure Main clauses: 4: Structure and overview - this standard supports and relates to ISO/IEC 27001 ; 5: Rationale - explains the value of measuring things e.g. to increase accountability and performance; 6: Characteristics - what to measure, monitor, analyse and evaluate, when to do it, and who should do it; 7: Types of measures - performance (efficiency) and effectiveness measures; 8: Processes - how to develop, implement and use metrics. Annex A is where most of the theoretical measurement model from the first edition of the standard now languishes. Annex B catalogs 35 metrics examples of varying utility and quality, using a typical metrics definition form. Annex C demonstrates a pseudo-mathematical way to describe a metric, or rather an ‘effectiveness measurement construct’ (!). Status The first edition was published in 2009 . It had a distinctly academic/theoretical style. A substantially revised (rewritten) second edition was published in 2016 . It is more practical. Work is under way on a third edition. The committee plans to: Update the main body and appendix references to reflect the 2022 editions of ISO/IEC 27001 , ISO/IEC 27002 and ISO/IEC 27005 . Adopt ISO’s version of plain English . This may involve extensive wording changes to make the standard easier to understand and apply. Provide additional metrics examples to suit organisations of all sizes. If all goes to plan, the third edition will be published before 2028. Commentary Since a management system is literally worse than useless without suitable metrics, it is appropriate for ISO/IEC 27001 to list this standard as a normative or essential standard. More than that, information security metrics are of value in all organisations, whether they have an ISO27k ISMS in place or not. I understand why ISO/IEC 27004 and several other ISO27k standards are aligned specifically to ISO/IEC 27001 : the narrow scope and tight focus increases the chances of the standards being completed and published in a reasonable timeframe (a problem that plagued the first edition of ISO/IEC 27004). That leaves a gap for broader-scope standards, including a general purpose information risk and security metrics standard ... or indeed an entire book . The example metrics in Annex B of the current second edition are a mixed bunch, poorly described. Please don’t think that you ought to be using them in your ISMS, unless they happen to address your specific management information needs. There are lots of moving parts to an ISMS, numerous objectives and hence plenty of measurable aspects. For example, the incident management process has numerous measureable parameters or factors at each of its eight phases: Prepare : readability of policies and procedures; team size, competencies; salaries. Identify : call-out rate; near-misses reported; Assess : incident breakdowns by type, severity etc .; Contain : investigation costs; business disruption; Investigate : incident root causes; causative factors; Resolve : impacts; time from occurrence to closure; repair costs; Learn : post-incident reviews completed; recurrent/persistent issues; actions arising; Overall : incident management process effectiveness and efficiency. The German standards body, DIN, suggested introducing the GQM (G oal-Q uestion-M etric) approach into the standard - an excellent idea raised too late for the second edition. Unfortunately, it seems the current revision is once again missing the opportunity for this worthwhile improvement. Meanwhile, Lance Hayden’s book “IT Security Metrics ” ably explains using GQM to identify possible metrics, while “PRAGMATIC Security Metrics ” by Brotby and Hinson describes a systematic method to evaluate them and improve their quality and value. Up Up Up This page last updated: 10 July 2026

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page