In 1990 the subcommittee SC 27 had its first meeting, and three decades later SC 27 it has developed into one of the largest committees in JTC 1 and an international centre for developing information security, cybersecurity and privacy protection standards.
SC 27 currently has over 1500 distinguished experts involved in delivering both management and technical standards and guidelines to address the challenges of information security and cybersecurity risks and the protection of personal data in our digitally connected world.
Three decades – many achievements
These have been 30 very productive and successful years of work resulting in many best-selling standards that have achieved global outreach and international market recognition. Over this time, our digital world has rapidly grown and diversified in many exciting and challenging ways, offering benefits and opportunities, as well as risks and uncertainties.
SC 27’s achievements include the world class flagship standards ISO/IEC 27001 and ISO/IEC 27002 and the establishment of an international centre for evaluation, testing, and assurance standards, known for the common criteria standard ISO/IEC 15408.
It is also a centre of crypto excellence attracting many of the worlds cryptographers responsible for developing standards that are used today to protect on-line purchasing, transactions and financial services, secure communications and storage, and many other uses.
SC 27 is at the forefront of developing security control and service standards to help protect our digital world and the technologies and devices we use. It also covers privacy protection standards and recently published ISO/IEC 27701 which extends ISO/IEC 27001 to the management of privacy information. With currently over 200 international standards, in 2015 SC 27 was also honoured with the prestigious ISO Lawrence D. Eicher Leadership Award.
Addressing market needs
SC 27 standards are produced in direct response to market needs, based on contributions delivered through a multi-stakeholder process involving relevant industry representatives and experts, governments, NGOs and other interested parties and stakeholders. This has involved SC 27 engaging with National Standards Bodies and their national experts, as well as with other ISO and IEC committees, standards organizations such as ITU-T, ETSI, CEN, and various liaison organizations.
Find out more about SC 27
As part of its communications and outreach programme SC 27 has undertaken several activities including: (i) publishing its own e-journal three times a year – these journals contain articles from experts covering the use and application of SC 27 standards, as well as publishing an e-book twice a year that gives an overview its work programme, (ii) holding industry workshops alongside each of its bi-annual meetings (pre-COVID), (iii) working with UN agencies (UNECE and UNIDIR) on Gender Responsive Standards and Standards Development and Gender approaches to cybersecurity.

Recent Comments