ISO/IEC-27008 › Information technology - Security techniques - Guidelines for the assessment of information security controls
The following bibliographic material is provided to assist you with your purchasing decision:
This document provides guidance on reviewing and assessing the implementation and operation of information security controls, including the technical assessment of information system controls, in compliance with an organization's established information security requirements including technical compliance against assessment criteria based on the information security requirements established by the organization.
This document offers guidance on how to review and assess information security controls being managed through an Information Security Management System specified by ISO/IEC 27001.
It is applicable to all types and sizes of organizations, including public and private companies, government entities, and not-for-profit organizations conducting information security reviews and technical compliance checks.
To find similar documents by classification:
35.030 (IT Security Including encryption)
This document comes with our free Notification Service, good for the life of the document.
This document is available in either Paper or PDF format.
Customers who bought this document also bought:
ISO/IEC-27001Information security, cybersecurity and privacy protection - Information security management systems - Requirements
ISO/IEC-27002
Information security, cybersecurity and privacy protection - Information security controls
NFPA-13
Standard for the Installation of Sprinkler Systems
Document Number
ISO/IEC TS 27008:2019
Revision Level
1ST EDITION
Status
Current
Publication Date
Jan. 1, 2019
Committee Number
ISO/IEC JTC 1/SC 27