International

ISO/IEC 27007:2020

107 controls. 194 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

107 controls 194 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27007-4.1Auditing principles overview0
27007-4.2Integrity and ethical conduct0
27007-4.3Evidence-based approach1
27007-5.1Establishing the Audit Programme2
27007-5.2Audit Programme Objectives170
27007-5.3Audit Programme Risks0
27007-5.4Establishing the Programme Resources55
27007-5.5Implementing the Audit Programme2
27007-5.6Monitoring the Audit Programme2
27007-5.7Reviewing and Improving the Programme1
27007-6.1Initiating the Audit1
27007-6.2Preparing Audit Activities1
27007-6.3Conducting Audit Activities1
27007-6.4Preparing and Distributing the Audit Report1
27007-6.5Completing the Audit1
27007-6.6Audit Follow Up0
27007-7.1Determining Auditor Competence1
27007-7.2Auditor Evaluation Criteria1
27007-7.3Selection of Auditor Evaluation Method0
27007-7.4Conducting Auditor Evaluation1
27007-7.5Maintaining and Improving Auditor Competence1
27007-A.1Generic Competence0
27007-A.2Discipline Specific Competence0
27007-A.4Auditing context of the organization (Clause 4)0
27007-A.5Auditing leadership (Clause 5)0
27007-A.6Auditing planning (Clause 6)0
27007-A.7-10Auditing support through improvement (Clauses 7-10)0
27007-B.1Practical Guidance Examples0
1-3Scope, normative references, terms and definitions0
4Principles of auditing0
5Managing an audit programme0
5.1General: establishing the audit programme0
5.2Establishing audit programme objectives0
5.3Determining and evaluating audit programme risks and opportunities0
5.4Establishing audit programme0
5.4.1Roles and responsibilities of the individual(s) managing audit programme0
5.4.2Competence of individual(s) managing audit programme0
5.4.3Establishing extent of the audit programme0
5.4.4Determining audit programme resources0
5.5Implementing audit programme0
5.5.2Defining the objectives, scope and criteria for an individual audit0
5.5.3Selecting and determining audit methods0
5.5.4Selecting audit team members0
5.5.5Assigning responsibility for an individual audit to the audit team leader0
5.5.6Managing audit programme results0
5.5.7Managing and maintaining audit programme records0
5.6Monitoring audit programme0
5.7Reviewing and improving audit programme0
6Conducting an audit0
6.2Initiating audit0
6.2.2Establishing contact with auditee0
6.2.3Determining feasibility of audit0
6.3Preparing audit activities0
6.3.1Performing review of documented information0
6.3.2Audit planning0
6.3.3Assigning work to audit team0
6.3.4Preparing documented information for audit0
6.4Conducting audit activities0
6.4.10Conducting closing meeting0
6.4.2Assigning roles and responsibilities of guides and observers0
6.4.3Conducting opening meeting0
6.4.4Communicating during audit0
6.4.5Audit information availability and access0
6.4.6Reviewing documented information while conducting audit0
6.4.7Collecting and verifying information0
6.4.8Generating audit findings0
6.4.9Determining audit conclusions0
6.5Preparing and distributing audit report0
6.5.1Preparing audit report0
6.5.2Distributing audit report0
6.6Completing audit0
6.7Conducting audit follow-up0
7Competence and evaluation of auditors0
7.2Determining auditor competence0
7.2.2Personal behaviour0
7.2.3Knowledge and skills0
7.2.4Achieving auditor competence0
7.2.5Achieving audit team leader competence0
7.3Establishing auditor evaluation criteria0
7.4Selecting appropriate auditor evaluation method0
7.5Conducting auditor evaluation0
7.6Maintaining and improving auditor competence0
AAnnex A (informative): guidance for ISMS auditing practice0
A:10.1Annex A: auditing ISO/IEC 27001:2013, 10.1 Nonconformity and corrective action0
A:10.2Annex A: auditing ISO/IEC 27001:2013, 10.2 Continual improvement0
A:4.1Annex A: auditing ISO/IEC 27001:2013, 4.1 Understanding the organization and its context0
A:4.2Annex A: auditing ISO/IEC 27001:2013, 4.2 Understanding the needs and expectations of interested parties0
A:4.3Annex A: auditing ISO/IEC 27001:2013, 4.3 Determining the scope of the information security management system0
A:4.4Annex A: auditing ISO/IEC 27001:2013, 4.4 Information security management system0
A:5.1Annex A: auditing ISO/IEC 27001:2013, 5.1 Leadership and commitment0
A:5.2Annex A: auditing ISO/IEC 27001:2013, 5.2 Policy0
A:5.3Annex A: auditing ISO/IEC 27001:2013, 5.3 Organizational roles, responsibilities and authorities0
A:6.1.1Annex A: auditing ISO/IEC 27001:2013, 6.1.1 Actions to address risks and opportunities: general0
A:6.1.2Annex A: auditing ISO/IEC 27001:2013, 6.1.2 Information security risk assessment0
A:6.1.3Annex A: auditing ISO/IEC 27001:2013, 6.1.3 Information security risk treatment0
A:6.2Annex A: auditing ISO/IEC 27001:2013, 6.2 Information security objectives and planning to achieve them0
A:7.1Annex A: auditing ISO/IEC 27001:2013, 7.1 Resources0
A:7.2Annex A: auditing ISO/IEC 27001:2013, 7.2 Competence0
A:7.3Annex A: auditing ISO/IEC 27001:2013, 7.3 Awareness0
A:7.4Annex A: auditing ISO/IEC 27001:2013, 7.4 Communication0
A:7.5Annex A: auditing ISO/IEC 27001:2013, 7.5 Documented information0
A:8.1Annex A: auditing ISO/IEC 27001:2013, 8.1 Operational planning and control0
A:8.2Annex A: auditing ISO/IEC 27001:2013, 8.2 Information security risk assessment (operation)0
A:8.3Annex A: auditing ISO/IEC 27001:2013, 8.3 Information security risk treatment (operation)0
A:9.1Annex A: auditing ISO/IEC 27001:2013, 9.1 Monitoring, measurement, analysis and evaluation0
A:9.2Annex A: auditing ISO/IEC 27001:2013, 9.2 Internal audit0
A:9.3Annex A: auditing ISO/IEC 27001:2013, 9.3 Management review0

Tell me when ISO/IEC 27007:2020 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Policy referencing the control
  • Documented procedure
  • Evidence of operating effectiveness
  • Monitoring or review reports
  • Roles and responsibilities mapping
  • Validation plan
  • Incident investigation report
  • OH&S audit plan
  • Management review minutes
  • Corrective action register

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27007:2020, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition