ISO/IEC-27009 › Information technology - Security techniques - Sector-specific application of ISO/IEC 27001 - Requirements
The following bibliographic material is provided to assist you with your purchasing decision:
ISO/IEC 27009:2016 defines the requirements for the use of ISO/IEC 27001 in any specific sector (field, application area or market sector). It explains how to include requirements additional to those in ISO/IEC 27001, how to refine any of the ISO/IEC 27001 requirements, and how to include controls or control sets in addition to ISO/IEC 27001:2013, Annex A.
It ensures that additional or refined requirements are not in conflict with the requirements in ISO/IEC 27001.
It is applicable to those involved in producing sector-specific standards that relate to ISO/IEC 27001.
To find similar documents by classification:
03.100.70 (Management systems Standards included in this sub-group shall also be included in other groups and/or sub-groups according to their subject Including environmental management systems (EMS), road traffic management systems, energy management systems, health care management systems, etc.)
This document comes with our free Notification Service, good for the life of the document.
This document is available in either Paper or PDF format.
June 15, 2016
ISO/IEC JTC 1/SC 27