Committee Draft
ISO/IEC CD TS 27008
Information technology — Security techniques — Guidelines for the assessment of information security controls
Reference number
ISO/IEC CD TS 27008
Edition 2
Committee Draft
ISO/IEC CD TS 27008
84242
A draft is being reviewed by the committee.
Will replace ISO/IEC TS 27008:2019

Abstract

This document provides guidance on reviewing and assessing the implementation and operation of information security controls, including the technical assessment of information system controls, in compliance with an organization's established information security requirements including technical compliance against assessment criteria based on the information security requirements established by the organization.

This document offers guidance on how to review and assess information security controls being managed through an Information Security Management System specified by ISO/IEC 27001.

It is applicable to all types and sizes of organizations, including public and private companies, government entities, and not-for-profit organizations conducting information security reviews and technical compliance checks.

General information

  •  : Under development
    : Close of comment period [30.60]
  •  : 2
  • ISO/IEC JTC 1/SC 27
  • RSS updates

Got a question?

Check out our Help and Support