ISO Releases International Standard for Information Security Control Assessment to Enhance Data Protection
Date:2019-03-25

Numerous information security risks such as software attacks, intellectual property theft and information sabotage may trigger severe consequences, yet these risks are merely the tip of the iceberg amid challenges faced by most organizations. While most organizations have established control measures to safeguard data security, how can we guarantee that such controls are sufficiently effective? The newly released international standard by ISO concerning the assessment of security controls can offer solutions.

For any organization, information ranks among its most valuable assets. Data breaches may lead to massive business losses and enormous recovery costs for enterprises. Therefore, existing control measures must be reinforced to secure data, accompanied by regular data monitoring to address evolving risks.

ISO/IEC TS 27008 Information technology — Security techniques — Guidelines for the assessment of information security controls is jointly developed by ISO and the International Electrotechnical Commission (IEC). It provides assessment guidelines for existing controls to ensure they function as intended, operate robustly and efficiently, and align with corporate objectives.

This recently revised Technical Specification (TS) is designed to align with updated editions of other information security management standards including ISO/IEC 27000 (Overview and vocabulary), ISO/IEC 27001 (Requirements) and ISO/IEC 27002 (Code of practice for information security controls). All these complementary standards are referenced within the updated Technical Specification.

Edward Humphreys, convener of the working group responsible for developing this standard, stated that ISO/IEC 27001 enables organizations to evaluate and review relevant controls, and the implementation of ISO/IEC TS 27008 will facilitate the assessment and audit of such controls.

Professor Edward Humphreys commented: “In today’s landscape, cyberattacks have become far more frequent, alongside growing difficulty in their detection and prevention. Regular assessment and audit of existing security controls should become a vital component of an organization’s business processes.”

“ISO/IEC TS 27008 helps organizations build confidence by verifying the effectiveness, sufficiency and appropriateness of their controls, and mitigates information risks borne by organizations.”

ISO/IEC TS 27008 delivers benefits to all types and sizes of organizations, whether public, private or non-profit. This standard serves as a supplement to the Information Security Management System defined in ISO/IEC 27001.

This standard was formulated by SC 27, the IT Security Techniques Subcommittee under ISO/IEC JTC 1 Information Technology Committee. Its secretariat is undertaken by DIN, the German national member body of ISO.


Tel:021-6409 0330
         13917723034

Email:info@huawayda.com

© Copyright Huaweida Testing & Certification (Shanghai) Co., Ltd. All Rights Reserved ICP Filing/License No.: 16029900-1