Skip to main content
Category: Audit Process

ISO/IEC 27007

Also known as: ISO 27007, ISO/IEC 27007:2020
Simply put

ISO/IEC 27007 is a guidance document that helps organizations plan and carry out audits of an information security management system (ISMS), the kind of system defined by ISO/IEC 27001. Rather than setting requirements that an organization must certify against, it offers practical advice on how to run an audit programme, conduct the audits themselves, and judge whether auditors have the right competence. It is a supporting standard used by internal audit teams and, in many engagements, by external auditors.

Formal definition

ISO/IEC 27007 is a guidance standard within the ISO/IEC 27000 family that addresses the auditing of information security management systems. According to the evidence, it provides guidance on managing an ISMS audit programme, on conducting audits, and on the competence of auditors, and it is applicable to those needing to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme. It is a supporting document rather than a certifiable requirements standard; the certifiable ISMS requirements reside in the clauses of ISO/IEC 27001, and ISO/IEC 27007 is used to inform how audits against those requirements are planned and executed. The standard has been issued in multiple editions (including 2011, 2017, and 2020 versions noted in the evidence), so practitioners should cite the specific edition applicable to their engagement.

Why it matters

ISO/IEC 27001 certification depends on rigorous, credible auditing of the information security management system, both through the organization's own internal audits and through the external audits conducted by an accredited certification body. ISO/IEC 27007 matters because it provides the practical guidance that helps make those audits consistent, competent, and defensible. Without shared guidance on how to plan an audit programme, conduct the audits, and evaluate auditor competence, audit quality can vary widely, which in turn affects the reliability of any certification decision that rests on those audit findings.

Who it's relevant to

Internal audit teams
Staff responsible for the internal audits required to maintain an ISMS use ISO/IEC 27007 to structure their audit programme, plan individual audits, and conduct them in a consistent way. The evidence identifies internal auditors as a primary audience for the standard.
External and certification-body auditors
Auditors conducting external audits of an ISMS, including those working on behalf of certification bodies in many engagements, can use ISO/IEC 27007 as guidance on how audits are conducted and how auditor competence is evaluated. The standard is expressly applicable to those needing to conduct external audits of an ISMS.
Audit programme managers
Those responsible for managing an ISMS audit programme use the standard for guidance on planning, resourcing, and overseeing that programme over time. Managing an ISMS audit programme is one of the three areas the guidance explicitly addresses.
GRC and compliance professionals overseeing ISO 27001
Compliance and governance teams responsible for maintaining ISO/IEC 27001 certification benefit from understanding ISO/IEC 27007 because it informs how audits against the certifiable ISO/IEC 27001 requirements are planned and executed. Note that the standard is guidance only and is not itself a certifiable requirements document.

Inside ISO/IEC 27007

Auditing guidelines for the ISMS
ISO/IEC 27007 provides guidance on auditing an information security management system (ISMS), building on the general management system auditing guidance found in ISO 19011 and tailoring it to the specific requirements of ISO/IEC 27001 clauses 4 through 10.
Guidance on the audit programme
It offers direction on establishing, implementing, and managing an audit programme, including planning audits, defining scope and objectives, and allocating resources appropriately to the ISMS context.
Auditor competence considerations
It addresses the knowledge and skills relevant to those auditing an ISMS, helping organizations and audit teams evaluate the competence needed to assess information security controls and processes.
Support for both internal and external audits
The guidance can inform internal audits conducted by an organization on its own ISMS as well as audits performed by certification bodies, though it is a supporting guidance document rather than a certifiable standard itself.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27007.

Is ISO/IEC 27007 a certifiable standard that my organization can achieve?
No. ISO/IEC 27007 is guidance, not a requirements standard, so an organization is not certified against it. Certification is issued against ISO/IEC 27001, whose certifiable requirements sit in clauses 4 through 10. ISO/IEC 27007 provides guidance to support the auditing of an information security management system, but it is not itself the basis for a certificate.
Does ISO/IEC 27007 replace or duplicate the general auditing guidance in ISO 19011?
No. ISO/IEC 27007 does not replace ISO 19011; it is intended to work alongside general management system auditing guidance by adding considerations specific to auditing an information security management system. Treating it as a standalone substitute for broader auditing guidance would misrepresent its purpose and scope.
Who typically uses ISO/IEC 27007 in practice?
In most cases it is used by those planning, conducting, or managing audits of an ISMS. This can include internal audit teams and, depending on the arrangement, personnel involved in supplier or second-party audits. Auditors working on behalf of accredited certification bodies also operate within their own accreditation and audit requirements, so the way the guidance is applied depends on the audit context.
How does ISO/IEC 27007 relate to a certification audit conducted by an accredited body?
ISO/IEC 27007 offers guidance that can inform how ISMS audits are approached, but a certification audit against ISO/IEC 27001 is governed by the certification body's accreditation requirements. The guidance can support audit planning and execution, yet the formal certification outcome depends on the certification body, the defined scope of the ISMS, and conformity with the ISO/IEC 27001 requirements rather than on ISO/IEC 27007 itself.
Can we use ISO/IEC 27007 to structure our internal ISMS audit program?
Many organizations draw on it to help shape internal ISMS audits, since internal audit is one of the ISMS requirements within ISO/IEC 27001. How much of the guidance you adopt typically depends on the maturity of your program, the scope of the ISMS, and your internal audit objectives. It provides considerations to inform the audit approach rather than a mandatory checklist.
Does following ISO/IEC 27007 guarantee our ISMS will pass certification?
No. Using the guidance may help strengthen how audits are planned and performed, but it does not guarantee a certification outcome. Certification depends on conformity with the ISO/IEC 27001 requirements as assessed by the certification body, the defined scope, and the effectiveness of the ISMS. The guidance supports auditing activities; it does not attest to or ensure any particular result.

Common misconceptions

ISO/IEC 27007 is a standard that organizations can be certified against.
ISO/IEC 27007 is a guidance document for auditing an ISMS, not a set of certifiable requirements. Certification is issued against ISO/IEC 27001 (its clauses 4 through 10) by an accredited certification body; ISO/IEC 27007 supports the auditing activity rather than serving as the basis for a certificate.
ISO/IEC 27007 replaces ISO 19011 for information security audits.
ISO/IEC 27007 supplements rather than replaces the general management system auditing guidance in ISO 19011, adapting it to the ISMS context. Practitioners typically use them together rather than treating one as a substitute for the other.
Following ISO/IEC 27007 makes an ISMS audit mandatory or dictates a single required approach.
As a guidance document, ISO/IEC 27007 offers recommendations rather than mandatory rules. How audits are scoped and conducted depends on the organization, the audit objectives, and the certification body or internal audit function involved.

Best practices

Use ISO/IEC 27007 alongside ISO 19011, treating it as ISMS-specific supplementary guidance rather than a stand-alone auditing rulebook.
Anchor audit planning to the ISO/IEC 27001 requirements in clauses 4 through 10, and reference the Statement of Applicability and risk assessment when evaluating selected Annex A controls.
Assess audit team competence against the knowledge and skills relevant to information security before assigning auditors to an ISMS engagement.
Define the audit scope and objectives clearly at the outset, recognizing that the appropriate approach varies depending on the organization and whether the audit is internal or performed by a certification body.
Establish and manage a documented audit programme with adequate resources, using ISO/IEC 27007's guidance to inform planning and execution.
Remember that an audit informed by ISO/IEC 27007 evaluates the defined ISMS scope and does not by itself guarantee the absence of security incidents; document scope boundaries accordingly.