ISO/IEC TS 27008:2019

Information technology — Security techniques — Guidelines for the assessment of information security controls ISO/IEC TS 27008:2019

Publication date:   Jan 14, 2019

General information

90.60 Close of review   Jun 5, 2023

ISO/IEC

ISO/IEC JTC 1/SC 27 Information security, cybersecurity and privacy protection

Technical Specification

35.030   IT Security

Buying

Published

Language in which you want to receive the document.

Scope

This document provides guidance on reviewing and assessing the implementation and operation of information security controls, including the technical assessment of information system controls, in compliance with an organization's established information security requirements including technical compliance against assessment criteria based on the information security requirements established by the organization.
This document offers guidance on how to review and assess information security controls being managed through an Information Security Management System specified by ISO/IEC 27001.
It is applicable to all types and sizes of organizations, including public and private companies, government entities, and not-for-profit organizations conducting information security reviews and technical compliance checks.

Life cycle

PREVIOUSLY

WITHDRAWN
ISO/IEC TR 27008:2011

NOW

PUBLISHED
ISO/IEC TS 27008:2019
90.60 Close of review
Jun 5, 2023

REVISED BY

IN_DEVELOPMENT
ISO/IEC PWI TS 27008