Transitioning to ISO/IEC 27006:2015 / AMD 1
Action required
Action Required by March 31, 2022
CBs shall have completed the transition to ISO/IEC 27006:2015 AMD 1:2020, through office assessment, within 2 years from the last day of the month of publication of the amended standard.
Note 1: ISO/IEC 27006:2015 AMD 1:2020, was published on March 27, 2020 and is available for purchase.
Note 2: This transition limits the amended clauses that mentioned in ISO/IEC 27006: 2015 AMD 1:2020 and is not a routine transition from a version of a standard to another.
Affected customers
SCC MSAP customers accredited to ISO/IEC 27006:2015 AMD 1:2020, assessors and technical experts
Background
ISO/IEC 27006:2015 AMD 1:2020, was published on March 27, 2020
The General Assembly, acting on the recommendation of the Technical Committee, resolved that the Transitional Arrangement associated with ISO/IEC 27006:2015 AMD 1:2020 - Information technology - Security techniques - Requirements for bodies providing audit and certification of information security management systems – Amendment 1, will be two years from the last day of the month of publication of the amended standard.
Note 1: ISO/IEC 27006:2015 AMD 1:2020, was published on March 27, 2020.
Note 2: The transition is not a routine transition from one version of a standard to another. The transition only relates to the specific changes detailed in Amendment 1:2020.
(Source: IAF Technical Committee – Transitional Arrangement for ISO/IEC 27006:2015 AMD 1:2020)
New requirements
The following sections of ISO/IEC 27006:2015 AMD 1:2020 have been amended, updated and/or added as new requirements:
Sec 7.2.1.1 d
7.2.1.1 g (new)
8.2.1
9.3.1.1
B.2.1
B.3.6
B.6
Deadline
CBs shall have completed the transition to ISO/IEC 27006:2015 AMD1:2020, through office assessment, within 24 months from the last day of the month of publication of the amended standard.
ISO/IEC 27006:2015 AMD 1:2020, was published on March 27, 2020. Hence, the transition deadline will be March 31, 2022.
Questions?
Please contact Abdel Kassou, Manager, Compliance and Assessment Services, at abdel.kassou@scc-ccn.ca or +1 613 238 3222 for more information.