What is ISO 27007 about?
ISO 27007 discusses information security, cybersecurity and privacy protection. ISO 27007 provides guidance on managing an information security management system (ISMS) audit programme, on conducting audits, and on the competence of ISMS auditors, in addition to the guidance contained in ISO 19011.
ISO 27007 is applicable to you if you need to understand or conduct internal or external audits of an ISMS or to manage an ISMS audit programme.
NOTE: ISO 27006 provides requirements for auditing ISMS for third party certification. ISO 27007 can provide useful additional guidance.
Who is ISO 27007 for?
ISO 27007 on guidelines for information security management systems auditing is useful for:
- Anyone who has, or plans to implement, an ISMS based on ISO 27001
- External auditors who wish to perform ISMS audits
- Anyone needing insight into the practical aspects of how an ISO 27001 ISMS can and will be assessed
- Accredited certification bodies
- Auditors
Why should you use ISO 27007?
Information security needs to stay dynamic to respond to the changing and constantly evolving security needs of a world where data is a prime asset and can be targeted by hackers. ISMS respond to this need. ISMS are subject to internal and external audits to ensure that they are functioning as required. Auditors also need guidance to do their jobs accurately. This is where ISO 27007 comes in.
ISO 27007 provides guidance on managing an ISMS audit programme, on conducting audits and on the competence of ISMS auditors. ISO 27007 follows the structure of and is to be used in conjunction with, the guidance contained in ISO 19011.
ISO 27007 provides guidance on auditing management systems and includes:
- The principles of auditing
- Managing an audit programme
- Conducting management system audits
- Guidance on evaluating the competence of individuals involved in the audit process. This includes the individual(s) managing the audit programme, auditors and audit teams
ISO 27007 contributes to UN Sustainable Development Goal 9 on industry, innovation and infrastructure.
What’s changed since the last update?
BS ISO/IEC 27007:2020 replaces the second edition ISO/IEC 27007:2017, which has been technically revised.
The main changes in BS ISO/IEC 27007:2020 compared to ISO/IEC 27007:2017 are as follows:
- The document has been aligned with ISO 19011:2018
- The Introduction has been reworded and expanded
- In clause 5.1, the entire text has been removed
- In clause 5.2.2, the former item d) has been removed
- In clause 5.3, the entire text has been removed

