CSA ISO/IEC TR 27008
Information technology - Security techniques - Guidelines for auditors on information security controls
|Publication Date:||1 January 2013|
|ICS Code (Information coding):||35.040|
This Technical Report provides guidance on reviewing the implementation and operation of controls, including technical compliance checking of information system controls, in compliance with an organization's established information security standards.
This Technical Report is applicable to all types and sizes of organizations, including public and private companies, government entities, and not-for-profit organizations conducting information security reviews and technical compliance checks. This Technical Report is not intended for management systems audits.