International

ISO/IEC 27006-1:2024

110 controls. 58 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

110 controls 58 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27006-5.1General Requirements for Certification Bodies1
27006-5.2Management of Impartiality0
27006-5.3Liability and Financing0
27006-6.1Competence of personnel0
27006-6.1.1Competence of Personnel0
27006-6.1.2Personnel Involved in Certification0
27006-6.1.3Use of Individual External Auditors and Technical Experts0
27006-6.2Personnel Records0
27006-7.1General competence requirements0
27006-7.1.1Determining Audit Time0
27006-7.1.2Multi-Site Sampling0
27006-7.1.3Technical knowledge requirements0
27006-7.2Audit Programme0
27006-7.3Stage 1 Audit0
27006-7.4Stage 2 Audit0
27006-7.5Surveillance Audits0
27006-7.6Recertification Audit0
27006-7.7Special Audits0
27006-7.8Reporting4
27006-8.1Certification Decision0
27006-8.2Suspension, Withdrawal, Reduction0
27006-8.2.3Referencing other standards0
27006-9.1Complaints and Appeals0
27006-9.1.3.3Remote audit provisions0
27006-9.2Management System Requirements2
27006-9.3Initial certification0
27006-9.3.2.2Certification decision process0
27006-9.4Surveillance and recertification53
27006-A.1Auditor Competence Areas0
27006-B.1Audit Time Determination0
27006-CAudit time guidance0
27006-DAudit time calculation methods0
27006-EControls alignment0
1-3Scope, normative references, terms and definitions0
10Management system requirements for certification bodies0
10.1.2ISMS implementation by the certification body0
10.2Option A: general management system requirements0
10.3Option B: management system requirements in accordance with ISO 90010
4Principles0
5General requirements0
5.1Legal and contractual matters0
5.2.2Conflicts of interest0
5.3Liability and financing0
6Structural requirements0
7Resource requirements0
7.1Competence of personnel0
7.1.2Generic competence requirements0
7.1.3Determination of competence criteria0
7.1.3.1Competence requirements for ISMS auditing0
7.1.3.1.1General requirements for audit team competence0
7.1.3.1.2Information security management terminology, principles, practices and techniques0
7.1.3.1.3Information security management system standards and normative documents0
7.1.3.1.4Business management practices0
7.1.3.1.5Client business sector0
7.1.3.1.6Client products, processes and organization0
7.1.3.2Competence requirements for conducting the application review0
7.1.3.2.1Application review: client business sector0
7.1.3.2.2Application review: client products, processes and organization0
7.1.3.3Competence requirements for reviewing audit reports and making certification decisions0
7.1.3.3.1Report review and decision: general0
7.1.3.3.2Report review and decision: information security management terminology, principles, practices and techniques0
7.1.3.3.3Report review and decision: client business sector0
7.1.3.3.4Report review and decision: client products, processes and organization0
7.2Personnel involved in the certification activities0
7.2.2Demonstration of auditor knowledge and experience0
7.2.2.1Demonstration of auditor knowledge and experience: general considerations0
7.2.2.2Selecting auditors0
7.3Use of individual external auditors and external technical experts0
7.4Personnel records0
7.5Outsourcing0
8Information requirements0
8.1Public information0
8.2Certification documents0
8.2.2ISMS certification documents0
8.2.3Reference of other standards in the ISMS certification documents0
8.3Reference to certification and use of marks0
8.4Confidentiality0
8.4.2Access to organizational records0
8.5Information exchange between a certification body and its clients0
9Process requirements0
9.1Pre-certification activities0
9.1.1Application0
9.1.2Application review0
9.1.3Audit programme0
9.1.4Determining audit time0
9.1.5Multi-site sampling0
9.1.6Multiple management systems0
9.2Planning audits0
9.2.1Determining audit objectives, scope and criteria0
9.2.2Audit team selection and assignments0
9.2.3Audit plan0
9.3Initial certification0
9.3.2Initial certification audit0
9.4Conducting audits0
9.4.2Specific elements of the ISMS audit0
9.4.3Audit report0
9.5Certification decision0
9.5.2Certification decision0
9.6Maintaining certification0
9.6.2Surveillance activities0
9.6.3Re-certification0
9.6.4Special audits0
9.6.5Suspending, withdrawing or reducing the scope of certification0
9.7Appeals0
9.8Complaints0
9.8.2Complaints0
9.9Client records0
AAnnex A (normative): knowledge and skills for ISMS auditing and certification0
B-D-EAnnexes B, D and E (informative): further competence considerations, audit time calculation methods, and guidance for review of implemented ISO/IEC 27001:2022 Annex A controls0
CAnnex C (normative): audit time0

Tell me when ISO/IEC 27006-1:2024 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Verification procedures
  • Verification reports
  • Sign-off records
  • Complaints register
  • Appeals process
  • Independent review records
  • Competence matrix for laboratory personnel
  • Training and qualification records
  • Authorization records for examination activities
  • Continuing professional development log

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27006-1:2024, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition