ISO/IEC 27006
ISO/IEC 27006 is an information security standard published by the International Organization for Standardization and the International Electrotechnical Commission. Part of the ISO/IEC 27000 series of ISO/IEC Information Security Management System standards, it is titled Information technology - Security techniques - Requirements for bodies providing audit and certification of information security management systems.
ISO/IEC 27006 lays out formal requirements for accredited organizations which certify other organizations compliant with ISO/IEC 27001.
It effectively replaces EA 7/03.
The standard helps ensure that ISO/IEC 27001 certificates issued by accredited organizations are meaningful and trustworthy, in other words it is a matter of assurance.
Description of standard
ISO 27006 outlines requirements to be accredited for third parties who audit and certify information security management systems, in addition to the requirements set by ISO 17021-1 and ISO 27001. This standard was first published in 2007, and it had to be revised twice due to significant changes made to ISO 17021 standard. The current version is ISO 27006 third edition published in 2015.ISO 27006:2015 sets standards for demonstration of ISMS auditors' competence. Certification Body auditing ISMS is required to verify each auditor on the auditing team has the knowledge of:
- ISMS monitoring, measurement, analysis, and evaluation,
- Information security,
- Management systems,
- Auditing principles, and
- Technical knowledge of systems to be audited.
Competence must also be demonstrated by personnel reviewing the audits and making certification decisions. They need to have sufficient knowledge to verify the accuracy of the certification scope. Also, they need to have general knowledge of management systems, audit procedures, principles, and techniques.
ISO27006:2015 also outlines adequate education, professional development, training covering ISMS audits, and current/relevant experience level.