ISO/IEC 27007
ISO/IEC 27007 is a guidance document that helps organizations plan and carry out audits of an information security management system (ISMS), the kind of system defined by ISO/IEC 27001. Rather than setting requirements that an organization must certify against, it offers practical advice on how to run an audit programme, conduct the audits themselves, and judge whether auditors have the right competence. It is a supporting standard used by internal audit teams and, in many engagements, by external auditors.
ISO/IEC 27007 is a guidance standard within the ISO/IEC 27000 family that addresses the auditing of information security management systems. According to the evidence, it provides guidance on managing an ISMS audit programme, on conducting audits, and on the competence of auditors, and it is applicable to those needing to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme. It is a supporting document rather than a certifiable requirements standard; the certifiable ISMS requirements reside in the clauses of ISO/IEC 27001, and ISO/IEC 27007 is used to inform how audits against those requirements are planned and executed. The standard has been issued in multiple editions (including 2011, 2017, and 2020 versions noted in the evidence), so practitioners should cite the specific edition applicable to their engagement.
Why it matters
ISO/IEC 27001 certification depends on rigorous, credible auditing of the information security management system, both through the organization's own internal audits and through the external audits conducted by an accredited certification body. ISO/IEC 27007 matters because it provides the practical guidance that helps make those audits consistent, competent, and defensible. Without shared guidance on how to plan an audit programme, conduct the audits, and evaluate auditor competence, audit quality can vary widely, which in turn affects the reliability of any certification decision that rests on those audit findings.
Who it's relevant to
Inside ISO/IEC 27007
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27007.