ISO/IEC TS 27008 provides guidance on reviewing and assessing the implementation and operation of information security controls, including the technical assessment of information system controls, in compliance with an organization's established information security requirements including technical compliance against assessment criteria based on the information security requirements established by the organization. ISO/IEC TS 27008 offers guidance on how to review and assess information security controls being managed through an Information Security Management System specified by ISO/IEC 27001.
ISO/IEC TS 27008 on information security controls is useful for:
Aim of the information security controls is to adequately mitigate information risks that the organization finds unacceptable and unavoidable, in a reasonably cost-effective and business-aligned manner. It offers the flexibility needed to customize the necessary reviews based on business missions and goals, organizational policies and requirements, known emerging threats and vulnerabilities, operational considerations, information system and platform dependencies, and the risk appetite of the organization.
Information security controls should be fit-for-purpose (meaning appropriate and suitable to the task at hand i.e. capable of mitigating information risks), effective (e.g. properly specified, designed, implemented, used, managed, and maintained) and efficient (delivering net value to the organization). ISO/IEC TS 27008 explains how to assess an organization’s information security controls against those and other objectives in order either to confirm that they are indeed fit-for-purpose, effective, and efficient (providing assurance), or to identify the need for changes (improvement opportunities).
ISO/IEC TS 27008:2019