ISO/IEC 27009 defines the requirements for the use of ISO/IEC 27001 in any specific sector (field, application area, or market sector). ISO/IEC 27009 explains how to include requirements additional to those in ISO/IEC 27001, how to refine any of the ISO/IEC 27001 requirements, and how to include controls or control sets in addition to ISO/IEC 27001:2013, Annex A. ISO/IEC 27009 ensures that additional or refined requirements are not in conflict with the requirements in ISO/IEC 27001. ISO/IEC 27009 is applicable to those involved in producing sector-specific standards that relate to ISO/IEC 27001.
ISO/IEC 27009 on security techniques is useful for:
ISO/IEC 27009 defines the requirements for establishing, implementing, maintaining, and continually improving an information security management system. ISO/IEC 27009 states that its requirements are generic and are intended to be applicable to all organizations, regardless of type, size, or nature.
ISO/IEC 27009 ensures that additional or refined sector-specific requirements are not in conflict with the requirements of ISO/IEC 27001. ISO/IEC 27009 mandates a standard structure and contents template for sector-specific information security management system (ISMS) standards. ISO/IEC 27009 provides guidance for developers of sector-specific information security management system (ISMS) standards. If its requirements are met, it will be possible for certification bodies using ISO/IEC 27006:2015 to certify information security management systems (ISMSs) built using the sector-specific standards against ISO/IEC 27001.
ISO/IEC 27009:2016