Overview
ISO/IEC 27007:2020 provides guidance for auditing information security, cybersecurity and privacy protection within an Information Security Management System (ISMS). It explains how to manage an ISMS audit programme, conduct internal and second‑party audits, and assess the competence of ISMS auditors. ISO/IEC 27007:2020 is aligned with ISO 19011:2018 and is intended to be used together with ISO/IEC 27000 and ISO/IEC 27001 where relevant. Annex A maps practical ISMS auditing guidance to ISO/IEC 27001:2013 requirements (Clauses 4–10).
Key Topics and Requirements
- Audit programme management
- Establishing objectives and scope for an ISMS audit programme
- Evaluating audit programme risks and opportunities
- Determining programme extent, resources and roles
- Monitoring, reviewing and improving the audit programme
- Conducting ISMS audits
- Initiating audits and establishing contact with the auditee
- Preparing (document review, planning, team assignments)
- Executing audit activities (information collection, verification, findings)
- Determining conclusions, reporting and follow‑up actions
- Auditor competence and evaluation
- Defining competence criteria for ISMS auditors and audit team leaders
- Personal behaviour and technical knowledge expected of auditors
- Methods for evaluating, maintaining and improving auditor competence
- Standards alignment and scope
- Guidance is supplemental to ISO 19011:2018 and complements ISO/IEC 27001-based audits
- Intended for internal and second‑party audits; ISO/IEC 27006 contains requirements for third‑party certification auditing
Practical Applications
ISO/IEC 27007:2020 is practical for organizations wanting to strengthen their information security audit practices:
- Internal audit teams seeking structured methods to audit an ISMS and report findings
- Audit programme managers who must design, resource and improve ISMS audit programmes
- Information security and compliance officers preparing for regulatory or supply‑chain assessments
- Second‑party auditors assessing external providers’ ISMS controls and privacy protection
- Organizations preparing for certification looking for additional guidance beyond ISO/IEC 27001 (note: certification audits follow ISO/IEC 27006)
Benefits include improved audit quality, clearer auditor competency expectations, more effective reporting and corrective action management, and better alignment between audits and organizational risk objectives.
Related Standards
Keywords: ISO/IEC 27007:2020, ISMS audit, information security audit, cybersecurity audit, privacy protection, audit programme, ISO 19011, auditor competence.