ISO 27009 discusses information security, cybersecurity and privacy protection. ISO 27009 specifies the requirements for creating sector-specific standards that extend ISO 27001, and complement or amend ISO 27002 to support a specific sector (domain, application area or market).
ISO 27009 specifies that additional or refined requirements do not invalidate the requirements in ISO 27001.
ISO 27009 is applicable to those involved in producing sector-specific standards.
ISO 27009 on requirements for creating sector-specific standards is useful for:
While ISO 27001 and ISO 27002 are widely accepted in organizations, including commercial enterprises, government agencies and not-for-profit organizations, there are needs for sector-specific versions of these standards.
ISO 27009 explains how to:
BS ISO/IEC 27009:2020 replaces ISO/IEC 27009:2016, which has been technically revised.
The main changes in BS ISO/IEC 27009:2020 compared to ISO/IEC 27009:2016 are as follows:
ISO/IEC 27009