ISO/IEC TR 27008:2011 Preview

Information technology -- Security techniques -- Guidelines for auditors on information security controls

ISO/IEC TR 27008:2011 provides guidance on reviewing the implementation and operation of controls, including technical compliance checking of information system controls, in compliance with an organization's established information security standards.

ISO/IEC TR 27008:2011 is applicable to all types and sizes of organizations, including public and private companies, government entities, and not-for-profit organizations conducting information security reviews and technical compliance checks. It is not intended for management systems audits.


General information

  • Current status : Published
    Publication date : 2011-10
  • Edition : 1
    Number of pages : 36
  • :
    ISO/IEC JTC 1/SC 27
    IT Security techniques
  • 03.100.70
    Management systems
    35.030
    IT Security

Buy this standard

Format Language
PDF
Paper
  • CHF158

Got a question?

Check out our FAQs


Customer care
+41 22 749 08 88

Opening hours:
Monday to Friday - 09:00-12:00, 14:00-17:00 (UTC+1)

You may be interested in:

http://www.iso.org/standard/
By Elizabeth Gasiorowski-Denis on
ISO/IEC guidelines to increase confidence in information security controls
An ISO/IEC technical report (TR) providing technical controls and compliance guidelines for auditors can improve the effectiveness of an organization’s information security system.

Keep up to date with ISO

Sign up to our newsletter for the latest news, views and product information