Skip to main content

BSI Standards

Please be advised that a New Work Item Proposal has been loaded to the BSI Standards Development Portal for comment. We hope this will assist in increasing awareness of the Standards Development Portfolio.

Any comments received will be submitted to IST/033/01 Information Security Management Systems, for consideration when deciding the UK response to CEN.

 Proposal: CEN/CLC/JTC 13 N 579 Requirements for bodies providing audit and certification of information security management systems — Part 1: General.

Please visit http://standardsdevelopment.bsigroup.com/projects/9022-06602
Comment period end date: 22/01/2022

Scope

ISO/IEC 27006-1 specifies requirements and provides guidance for bodies providing audit and certification of an information security management system (ISMS), in addition to the requirements contained within ISO/IEC 17021-1 and ISO/IEC 27001. It is primarily intended to support the accreditation of certification bodies providing ISMS certification. 

The requirements contained in this International Standard need to be demonstrated in terms of competence and reliability by any body providing ISMS certification, and the guidance contained in this International Standard provides additional interpretation of these requirements for any body providing ISMS certification.

NOTE This Standard can be used as a criteria document for accreditation, peer assessment or other audit processes.

Purpose

ISO/IEC 27006 is widely recognised standard within the 2700x ISMS family of standards. This standard is a fundamental basis for the certification of information security management systems The adoption as European Standard would harmonize the European market regarding the certification of Information security management systems.

 If you have any comment or need more information, please contact Sami Ortiz at sami.ortiz@mta.org.uk