BS ISO/IEC 27006 gives practical guidance for certification bodies and approval organizations that provide quality audits and the certification of information security management systems. These practical, hands-on guidelines are in addition to the requirements set out in BS ISO/IEC 17021 and BS ISO/IEC 27001. By following the recommendations in BS ISO/IEC 27006, approval organizations can demonstrate competence and reliability when performing an ISMS certification.
BS ISO/IEC 27006 looks at the general, legal and contractual requirements of an effective information security management system. This includes the management of computers, computer networks and data processing to ensure data security at all times. This standard also takes the organizational structure and top management into account, and highlights resource requirements and the personnel involved in the certification activities.
We are global, we’re independent and we’re a trusted service provider to 80,000 businesses. We operate in 147 countries and are the number one certification body in the UK and US. We created 85% of our portfolio because we know standards and we know your business. We’re leaders and we can make you one too.
ISO/IEC 27006:2007