ISO/IEC 27006-1:2024
Information security, cybersecurity and privacy protection — Requirements for bodies providing audit and certification of information security management systems — Part 1: General
Information security, cybersecurity and privacy protection — Requirements for bodies providing audit and certification of information security management systems — Part 1: General
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 47
- Дата публикации:
- 1 марта 2024 г.
- Издание:
- ISO/IEC IS 27006 edition 1 version 1
- ICS:
- 03.120.20
This document specifies requirements and provides guidance for bodies providing audit and certification of an information security management system (ISMS), in addition to the requirements contained within ISO/IEC 17021-1. The requirements contained in this document are demonstrated in terms of competence and reliability by bodies providing ISMS certification. The guidance contained in this document provides additional interpretation of these requirements for bodies providing ISMS certification. NOTE This document can be used as a criteria document for accreditation, peer assessment or other audit processes.
Abstract
Overview
ISO/IEC 27006-1:2024 - Part 1: General defines requirements and provides guidance for bodies that audit and certify Information Security Management Systems (ISMS). It supplements ISO/IEC 17021-1 by specifying how certification bodies must demonstrate competence, impartiality and reliability when issuing ISMS certifications. The standard is applicable as a criteria document for accreditation, peer assessment or other conformity assessment activities in the fields of information security, cybersecurity and privacy protection.
Key topics and requirements
ISO/IEC 27006-1:2024 covers the full certification lifecycle and organizational controls for certification bodies, including:
- Principles and legal/contractual matters: obligations related to contracts, liability and financing.
- Management of impartiality and conflicts of interest: mechanisms to ensure objective certification decisions.
- Structural and resource requirements: organizational structure, outsourcing, personnel records.
- Competence of personnel: generic and ISMS-specific competence criteria, auditor knowledge, use of external auditors and technical experts (Annex A - knowledge and skills).
- Information requirements: public information, certification documents, use of marks, confidentiality and information exchange with clients.
- Process requirements: pre-certification (application and review), audit planning, determining audit time and multi-site sampling (Annex C normative on audit time; Annex D on methods), initial certification audits, surveillance, re-certification, special audits and certification decision processes.
- Handling appeals and complaints and maintaining client records.
- Management system options: Option A (general MS requirements) or Option B (MS in accordance with ISO 9001).
- Guidance for ISO/IEC 27001:2022 Annex A control reviews (Annex E informative).
Applications and who should use it
ISO/IEC 27006-1:2024 is intended for:
- Certification bodies that issue ISMS certifications.
- Accreditation bodies using the document as an assessment criterion.
- Auditors and technical experts preparing for ISMS audits.
- Organizations seeking ISMS certification to understand certification body expectations.
- Regulators and procurement teams specifying certification requirements for suppliers.
Practical uses include designing auditor competency frameworks, calculating audit time for ISO/IEC 27001 assessments, structuring surveillance plans, and ensuring impartiality and confidentiality in certification activities.
Related standards
- ISO/IEC 17021-1 - general requirements for bodies providing audit and certification of management systems (baseline).
- ISO/IEC 27001:2022 - requirements for establishing, implementing and maintaining an ISMS (certification target).
- ISO 9001 - referenced for Management System Option B.
Keywords: ISO/IEC 27006-1:2024, ISMS certification, information security, cybersecurity, privacy protection, auditor competence, audit time, accreditation.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27006-1:2024
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 17021-13:2021
ДействующийConformity assessment. Requirements for bodies providing audit and certification of management systems. Compe…
ISO/TS 54001:2019
ДействующийQuality management systems — Particular requirements for the application of ISO 9001:2015 for electoral organ…
Overview ISO/TS 54001:2019 - Quality management systems - Particular requirements for the application of ISO 9001:2015 for electoral organizations at all levels of government - provides sector-specif…