ISO/IEC TR 27023 is a security standard on information technology.
The purpose of ISO/IEC TR 27023 is to show the corresponding relationship between the revised versions of ISO/IEC 27001 and ISO/IEC 27002.
ISO/IEC TR 27023 will be useful to all users migrating from 2005 to the 2013 versions of ISO/IEC 27001 and ISO/IEC 27002.
ISO/IEC TR 27023 on the security techniques of Information technology is relevant to:
Information technology is the use of any computers, storage, networking, and other physical devices, infrastructure, and processes to create, process, store, secure, and exchange all forms of electronic data.
ISO/IEC TR 27023 is designed to provide a factual correspondence between the old and new editions of ISO/IEC 27001 and ISO/IEC 27002 respectively, and so by intention, it does not provide any explanatory commentary on why a change has been made or the significance of the change. Users of this ISO/IEC TR 27023 need to evaluate the significance of the changes in context about their application and implementation of the revised editions of these standards. For ISO/IEC 27002, the comparison was based on control objectives, controls, and implementation guidance.
Overall, ISO/IEC TR 27023 can be used to determine where requirements or controls in the old standards went, or where requirements or controls in the new standards have come from.
ISO/IEC TR 27023:2015