ISO/IEC JTC 1/SC 27
Information security, cybersecurity and privacy protection
August 2025
ISO/IEC JTC 1/SC27 is an international recognized centre of information security, cybersecurity and privacy expertise serving the needs of a diverse range of business sectors as well as governments and consumer requirements for international standards.
History
The history of SC27 goes back to the early 80’s. At this time an ISO Technical Committee TC 97 established a working party to address the development of the first set of security standards in ISO. The TC 97 working party was chaired by the late Sir Donald Davis (UK) and had just five national bodies (NBs) as members: Germany (ZfCH), Netherlands, Switzerland (Walter Widmer), UK (Dr. Edward (Ted) Humphreys and Denis Willetts) and USA (Bob Elander).
ISO/TC 97/SC 20 developed out of TC 97. SC 20 had three working groups WG 1 Secret-key Techniques (Edward (Ted) Humphreys, UK), WG 2 Public-key Techniques (Louis Guillou, France) and WG 3 (Joe Tardo, USA). Denis Willetts (UK) was the Chair of SC 20 with Secretariat DIN Annette Calkin (GMD, Germany). Eventually SC 20 came under the wing of the newly formed joint committee ISO/IEC JTC 1. In 1989 SC 20 was disbanded and SC 27 was established in 1990 (per Resolution 28 of the Paris JTC 1 Plenary), which took over the work of SC 20 WG 1 and WG 2 well as establishing a new working group (WG3) to cover security evaluation criteria. In the late 90s and early 2000s WG 1 handed over its work on cryptography to WG 2, in order to focus entirely on information security management standards and the development of the now famous ISO/IEC 27001 family of standards. With the continuing extension of its scope to cover new areas of work, SC 27 in 2006, establish two further working groups WG 4 and WG 5.
Thirty-Five Years of Developing Standards
In 2020, SC 27 celebrates its 35th birthday this year, a significant milestone in the history of information security and privacy standards. During the past 35 years SC 27 has successfully applied the PDCA (Plan-Do-Check-Act) continual improvement model to adapt its standardization work to the changing security and privacy landscape. The committee has revised and extended its scope a number of times to reflect and reach out to new demands and emerging technologies from the market in areas such as information security management systems, cybersecurity, cryptographic algorithms, Cloud computing security and privacy, AI security, IoT security, Big Data, privacy protection techniques, identity management, or security aspects of biometrics.
SC 27 STRUCTURE
SC 27 MANAGEMENT
JTC 1/SC 27 Chairman: DIN, Germany, Dr. Andreas WOLF
JTC 1/SC 27 Chair-support: ANSI, United States, Laura LINDSAY
JTC 1/SC 27 Communications Officer: BSI, United Kingdom, Dr. Edward HUMPHREYS
JTC 1/SC 27 Committee Manager: DIN, Germany, Sobhi Mahmoud
JTC 1/SC 27 Secretariat: DIN, Germany
SC 27 WORKING GROUPS
WG 1: Information Security Management Systems
- Convenor: Dr. Edward HUMPHREYS, BSI, United Kingdom
- Convener support: Pablo CORONA, DGN, Mexico
- Convenor support team: Zhigao FU, SAC, China
WG 2: Cryptography and Security Mechanisms
- Convenor: Hirotaka YOSHIDA, JISC, Japan
- Convenor support: Takeshi CHIKAZAWA, JISC, Japan
WG 3: Security Evaluation, Testing and Specification
- Convenor: Miguel BAÑÓN, UNE, Spain
- Convenor support: Naruki KAI, JISC, Japan
WG 4: Security Controls and Services
- Convenor: Johann AMSENGA, ILNAS, Luxembourg
- Convenor support: François LOREK, AFNOR, France
WG 5: Identity Management and Privacy Technologies
- Convenor: Prof. Dr. Kai RANNENBERG, DIN, Germany
- Convenor support: Dr. Jan SCHALLABÖCK, DIN, Germany
SC 27 ADVISORY GROUPS
CAG (Chair’s Advisory Group)
- Convenor: Dr. Andreas WOLF, DIN, Germany
- Convenor support; Laura LINDSAY, ANSI, United States
AG-2 (Trustworthiness)
- Convenor: Ricardo VILLALON FONSECA, INTECO, Costa Rica
- Convenor support; Johann AMSENGA, ILNAS, Luxembourg
AG-5 (Strategy)
- Convenor: Jean-Pierre QUÉMARD, AFNOR, France
- Convenor support: Yan SUN, SAC, China
AG-6 (Operations)
- Convenor: Dr. Qin QIU, SAC, China
AG-7 (Communications and Outreach)
- Convenor: Dr. Edward HUMPHREYS, BSI, United Kingdom
- Convenor support: Taewan PARK, KATS, Republic of Korea
AG-8 (Advisory Group on Conformity Assessment)
- Convenor: Dr. Edward HUMPHREYS, BSI, United Kingdom
AG-9 (Advisory Group on Diversity)
- Convenor: Dr. Gargi KEENI, BIS, India
SC 27 JOINT WORKING GROUPS
ISO/TC 307-JTC 1/SC 27/JWG 4: Security, privacy and identity for Blockchain and DLT
- Co-Convenor: Julien BRINGER, AFNOR, France (appointed by ISO/TC 307)
- Co-Convenor: Sal FRANCOMACARO ANSI, USA (appointed by JTC 1/SC 27)
ISO/IEC JTC 1/SC 27 and SC 37 Joint Working Group: Cybersecurity testing and evaluation of biometric products.
- Co-Convenor: Julien BRINGER, AFNOR, France (appointed by JTC 1/SC27)
- Co-Convenor: Ambika, SUMAN (appointed by JTC 1/SC 27)
The structure of SC 27, as shown above, consists of five working groups, two joint working groups and seven advisory groups (above). The five working groups deal with all aspects of information security management systems, security techniques (including cryptographic algorithms), security evaluation and accreditation, to security controls and services, through to privacy technology standards and identity management.
SC 27 has developed many well-known and celebrated best-selling ISO standard ISO/IEC 27001 (ISMS requirements) ranked 3rd in the ISO survey of management system standards, the high profile, the best-selling ISO standards ISO/IEC 27002 (information security controls) and ISO/IEC 27005 (Information security risk management), ISO/IEC 15408 (security evaluation criteria for IT security) and the recently published ISO/IEC 27701(for privacy information management). The SC 27 portfolio also includes many notable crypto standards and service and control standards in widespread use in business and industry.
SC 27 also collaborates with many standards committees in ISO, IEC and JTC 1 on the security privacy aspects of their work, for example, with a joint working group with ISO/TC 307/JWG 4 on Security, privacy and identity for blockchain and DLT, JTC 1/SC 37 on biometrics, SC 38 on Cloud computing, SC 41 on IoT, SC 42 on AI, and a joint working group with TC 22/SC 32 on cybersecurity and connected vehicle devices. Also, SC 27 collaborates with external groups such as ITU-T SG 17 on collaborative common-text projects such as ITU-T X.1051|ISO/IEC 27011 (telecoms use of ISO/IEC 27002), X.842|ISO/IEC 14516 (guidelines for TTP services) and X.843| ISO/IEC 15945 (TTP services to support digital signatures) and ITU-T X.1054 | ISO/IEC 27014 (governance of information security), and ETSI on crypto, security services and controls.
SC 27 works closely with CASCO on conformity assessment aspects of its standards, and with TMBG/JTCG on management system standards (including Directives Part 1 Annex SL) and IAF on accreditation/certification aspects related to ISO/IEC 27001 and ISO/IEC 27701.

Figure 1 Landscape of SC 27 standards work
-
- SC 27 has increased committee membership from 18 P-members in 1990 to 53 P-members and 37 O-members in 2024, covering a vast and diverse number of geographic areas of the globe, with over 2000 registered experts from a diverse range of industries. SC 27 meetings are typically attended by more than 320 participants.
- SC27 has brought together many of the world’s leading information security, cyber security and privacy experts, which so far have been involved in more than 295 projects: 246 publications and 49 standards under development, including some of the most successful security standards within ISO/IEC.
- SC 27 has ‘top-class’ professionals and a global outreach that enables it to produce quality standards that serve all the major market sectors and multi-stakeholder interests.
In 2015 the success story of SC 27 was honoured with the prestigious Lawrence D. Eicher Award, which is given each year to the ISO technical committee or subcommittee
that has distinguished itself in making significant contributions to the development of International Standards.
The mission statement of SC 27 has remained unchanged during these 35 years, that is, to deliver quality generic standards for its discerning customer base. With this in mind, SC 27 continues to engage in standardisation work at the forefront of the marketplace, embracing the requirements of new and emerging technologies and business innovations.
Focusing on the development of generic standards for information security, cybersecurity and privacy and this has led to a considerable number of liaisons to other standardization and industry bodies. Many of these liaison bodies typically use SC 27 standards and technical reports as a basis for developing their own security implementation standards specific for their sector such as telecom, finance, utilities, healthcare, and transport. For more information on SC 27 and its work programme, the reader is referred to https://committee.iso.org/home/jtc1sc27/ in particular, a more detailed overview of its work can be found in the Committee Document CD 11, available from the SC 27 web site.
Finally, SC 27 has a proactive communications and outreach group promoting and publicizing the work of SC 27. This includes a SC 27 Journal published three times a year, containing articles by experts on standards developed by SC 27, also CD 11 (mentioned above), workshops and supporting ISO and IEC with their articles.