40.20 DIS ballot initiated: 12 weeks Jul 2, 2026
CEN/CENELEC
CEN/CLC/JTC 13 Cybersecurity and Data Protection
European Norm
35.030 IT Security
This document provides guidance on managing an information security management system (ISMS) audit programme, on conducting audits, and on the competence of ISMS auditors, in addition to the guidance contained in ISO 19011.
This document is applicable to those needing to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme.
PUBLISHED
EN ISO/IEC 27007:2022
IN_DEVELOPMENT
prEN ISO/IEC 27007
40.20
DIS ballot initiated: 12 weeks
Jul 2, 2026