27006-5.1 | General Requirements for Certification Bodies | 1 |
27006-5.2 | Management of Impartiality | 0 |
27006-5.3 | Liability and Financing | 0 |
27006-6.1 | Competence of personnel | 0 |
27006-6.1.1 | Competence of Personnel | 0 |
27006-6.1.2 | Personnel Involved in Certification | 0 |
27006-6.1.3 | Use of Individual External Auditors and Technical Experts | 0 |
27006-6.2 | Personnel Records | 0 |
27006-7.1 | General competence requirements | 0 |
27006-7.1.1 | Determining Audit Time | 0 |
27006-7.1.2 | Multi-Site Sampling | 0 |
27006-7.1.3 | Technical knowledge requirements | 0 |
27006-7.2 | Audit Programme | 0 |
27006-7.3 | Stage 1 Audit | 0 |
27006-7.4 | Stage 2 Audit | 0 |
27006-7.5 | Surveillance Audits | 0 |
27006-7.6 | Recertification Audit | 0 |
27006-7.7 | Special Audits | 0 |
27006-7.8 | Reporting | 4 |
27006-8.1 | Certification Decision | 0 |
27006-8.2 | Suspension, Withdrawal, Reduction | 0 |
27006-8.2.3 | Referencing other standards | 0 |
27006-9.1 | Complaints and Appeals | 0 |
27006-9.1.3.3 | Remote audit provisions | 0 |
27006-9.2 | Management System Requirements | 2 |
27006-9.3 | Initial certification | 0 |
27006-9.3.2.2 | Certification decision process | 0 |
27006-9.4 | Surveillance and recertification | 53 |
27006-A.1 | Auditor Competence Areas | 0 |
27006-B.1 | Audit Time Determination | 0 |
27006-C | Audit time guidance | 0 |
27006-D | Audit time calculation methods | 0 |
27006-E | Controls alignment | 0 |
1-3 | Scope, normative references, terms and definitions | 0 |
10 | Management system requirements for certification bodies | 0 |
10.1.2 | ISMS implementation by the certification body | 0 |
10.2 | Option A: general management system requirements | 0 |
10.3 | Option B: management system requirements in accordance with ISO 9001 | 0 |
4 | Principles | 0 |
5 | General requirements | 0 |
5.1 | Legal and contractual matters | 0 |
5.2.2 | Conflicts of interest | 0 |
5.3 | Liability and financing | 0 |
6 | Structural requirements | 0 |
7 | Resource requirements | 0 |
7.1 | Competence of personnel | 0 |
7.1.2 | Generic competence requirements | 0 |
7.1.3 | Determination of competence criteria | 0 |
7.1.3.1 | Competence requirements for ISMS auditing | 0 |
7.1.3.1.1 | General requirements for audit team competence | 0 |
7.1.3.1.2 | Information security management terminology, principles, practices and techniques | 0 |
7.1.3.1.3 | Information security management system standards and normative documents | 0 |
7.1.3.1.4 | Business management practices | 0 |
7.1.3.1.5 | Client business sector | 0 |
7.1.3.1.6 | Client products, processes and organization | 0 |
7.1.3.2 | Competence requirements for conducting the application review | 0 |
7.1.3.2.1 | Application review: client business sector | 0 |
7.1.3.2.2 | Application review: client products, processes and organization | 0 |
7.1.3.3 | Competence requirements for reviewing audit reports and making certification decisions | 0 |
7.1.3.3.1 | Report review and decision: general | 0 |
7.1.3.3.2 | Report review and decision: information security management terminology, principles, practices and techniques | 0 |
7.1.3.3.3 | Report review and decision: client business sector | 0 |
7.1.3.3.4 | Report review and decision: client products, processes and organization | 0 |
7.2 | Personnel involved in the certification activities | 0 |
7.2.2 | Demonstration of auditor knowledge and experience | 0 |
7.2.2.1 | Demonstration of auditor knowledge and experience: general considerations | 0 |
7.2.2.2 | Selecting auditors | 0 |
7.3 | Use of individual external auditors and external technical experts | 0 |
7.4 | Personnel records | 0 |
7.5 | Outsourcing | 0 |
8 | Information requirements | 0 |
8.1 | Public information | 0 |
8.2 | Certification documents | 0 |
8.2.2 | ISMS certification documents | 0 |
8.2.3 | Reference of other standards in the ISMS certification documents | 0 |
8.3 | Reference to certification and use of marks | 0 |
8.4 | Confidentiality | 0 |
8.4.2 | Access to organizational records | 0 |
8.5 | Information exchange between a certification body and its clients | 0 |
9 | Process requirements | 0 |
9.1 | Pre-certification activities | 0 |
9.1.1 | Application | 0 |
9.1.2 | Application review | 0 |
9.1.3 | Audit programme | 0 |
9.1.4 | Determining audit time | 0 |
9.1.5 | Multi-site sampling | 0 |
9.1.6 | Multiple management systems | 0 |
9.2 | Planning audits | 0 |
9.2.1 | Determining audit objectives, scope and criteria | 0 |
9.2.2 | Audit team selection and assignments | 0 |
9.2.3 | Audit plan | 0 |
9.3 | Initial certification | 0 |
9.3.2 | Initial certification audit | 0 |
9.4 | Conducting audits | 0 |
9.4.2 | Specific elements of the ISMS audit | 0 |
9.4.3 | Audit report | 0 |
9.5 | Certification decision | 0 |
9.5.2 | Certification decision | 0 |
9.6 | Maintaining certification | 0 |
9.6.2 | Surveillance activities | 0 |
9.6.3 | Re-certification | 0 |
9.6.4 | Special audits | 0 |
9.6.5 | Suspending, withdrawing or reducing the scope of certification | 0 |
9.7 | Appeals | 0 |
9.8 | Complaints | 0 |
9.8.2 | Complaints | 0 |
9.9 | Client records | 0 |
A | Annex A (normative): knowledge and skills for ISMS auditing and certification | 0 |
B-D-E | Annexes B, D and E (informative): further competence considerations, audit time calculation methods, and guidance for review of implemented ISO/IEC 27001:2022 Annex A controls | 0 |
C | Annex C (normative): audit time | 0 |