# iec — RSS Amplifier

Recent posts from the 2 feeds in the RSS Amplifier directory that cover iec.

Page: <https://rssamplifier.com/topics/iec>  
Feed: <https://rssamplifier.com/topics/iec.md>

---

## [ISO/IEC 27017 (cloud security) updated](https://www.iso27001security.com/post/iso-iec-27017-cloud-security-updated)

_2026-08-18 · Gary Hinson · ISO27001security_

After more than a decade, the first edition of ISO/IEC 27017 and ITU-T recommendation X.1631 has been updated. The standard advises both Cloud Service Customers and Cloud Service Providers, providing complementary security guidance side-by-side in tables. Clauses 5 through 8 in the new second edition adopt the structure of ISO/IEC 27002:2022: Clause 4 sets the scene with general guidance and…

## [ISO/IEC 4213 2nd edition reaches Draft International Standard stage](https://adamleonsmith.substack.com/p/isoiec-4213-2nd-edition-reaches-draft)

_2026-08-03 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

From a technical specification to the standard nobody can avoid

## [prEN 18229-3 reaches Enquiry](https://adamleonsmith.substack.com/p/pren-18229-3-reaches-enquiry)

_2026-07-30 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

The standard that admits human oversight sometimes cannot work

## [Revised AI Act text available](https://adamleonsmith.substack.com/p/revised-ai-act-text-available)

_2026-07-24 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

My shortest article of all time.

## [EN 18286:2026 is finally published, the first AI Act standard to reach that milestone](https://adamleonsmith.substack.com/p/en-182862026-is-finally-published)

_2026-07-22 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

What changed since the public enquiry version?

## [Generic infosec controls](https://www.iso27001security.com/post/generic-infosec-controls)

_2026-07-19 · Gary Hinson · ISO27001security_

ISO/IEC JTC 1/SC 27 is in the early stages of updating ISO/IEC 27002:2022 - the generic set of information security controls generally worth considering, whether as part of a '27001 Information Security Management System or not. Rather than leaping straight into the usual process of inviting then discussing and addressing comments and proposed changes, the revision project's editorial team is…

## [Adversaries as 'interested parties'](https://www.iso27001security.com/post/adversaries-as-interested-parties)

_2026-07-15 · Gary Hinson · ISO27001security_

ISO/IEC 27000:2016 clause 4.4 "Why an ISMS is important" explained the purpose of information security and an ISMS in about a page of 7 paragraphs. In ISO/IEC 27000:2026, that clause became 4.1.7 "Importance of an ISMS" and was condensed to half a page with 3 paragraphs. It's more than just a tightening-up of the wording, though, including this new text: "Interested parties can include not only…

## [Slimline ISO/IEC 27000 published](https://www.iso27001security.com/post/slimline-iso-iec-27000-published)

_2026-07-05 · Gary Hinson · ISO27001security_

The brand new 2026 sixth edition of ISO/IEC 27000 takes just 11 shiny pages to outline an Information Security Management System and succinctly summarise a fifth of the ~100 ISO/IEC 27xxx (ISO27k) standards. Gone are 65 of the previous edition's definition of terms, leaving just 12, of which all bar 5 are shortened versions of definitions drawn from other ISO27k standards. The most useful part is…

## [Updated ISO/IEC Directives](https://www.iso27001security.com/post/updated-iso-iec-directives)

_2026-07-02 · Gary Hinson · ISO27001security_

In three months (October 5th this year), an updated set of ISO/IEC directives will come into force. While most of the changes relate to the internal management structures of committees and projects, aligning ISO and IEC and simplifying the directives, the timescales for standards development are being tightened-up with implications for the way standards work is initiated, specified, planned and…

## [prEN ISO/IEC DIS 23282: How to measure whether Natural Language AI is accurate](https://adamleonsmith.substack.com/p/pren-isoiec-dis-23282-how-to-measure)

_2026-06-30 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

What the new NLP evaluation standard covers, and why providers of high-risk and general-purpose AI should read it

## [Hire AI-Powered Professionals (Sponsored)](https://crawlproof.com/a/m6SrOC33HnIz)

_2026-06-30 · **Sponsored**_

Browse public gigs, message candidates, and run video interviews — free to start.

## [AI security standard 27090](https://www.iso27001security.com/post/ai-security-standard-27090)

_2026-06-06 · Gary Hinson · ISO27001security_

Earlier today I blogged about the tedium and risks of ISO's slow processes, both consequences of the effort needed to align all those involved in standardisation and produce worthwhile, generally-acceptable standards. Here's another topical example. ISO/IEC 27090 "Cybersecurity — Artificial Intelligence — Guidance for addressing security threats and compromises to artificial intelligence systems"…

## [27000 &#38; 27017 updates "soon-as"](https://www.iso27001security.com/post/updated-27000-27017-soon)

_2026-06-05 · Gary Hinson · ISO27001security_

Updates to both ISO/IEC 27000 and ISO/IEC 27017 have passed their votes at FDIS stage. 27000 (the overview and introduction to the ISO27k standards) received just a few minor comments and should be released very soon (which means within months, in ISO-land). 27017 (cloud security) received about 10 pages of comments - mostly minor grammatical corrections though, so it too remains on-track for…

## [Two standards, one architecture: FprEN ISO/IEC FDIS 24970 and prEN 18229-1](https://adamleonsmith.substack.com/p/two-standards-one-architecture-fpren)

_2026-06-05 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

Two significant milestones landed this spring serving both the state of the art and Article 12 of the EU AI Act.

## [9 things to look for in compliant agentic AI](https://adamleonsmith.substack.com/p/9-things-to-look-for-in-compliant)

_2026-06-02 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

This article builds on the paper "AI Agents under EU Law" and a keynote presentation I gave to market surveillance authorities in May

## [You can't do AI ethics without AI ethicists](https://adamleonsmith.substack.com/p/you-cant-do-ai-ethics-without-ai)

_2026-06-01 · Enrico PANAI · AI regulation, standards and reality_

EN 18274 approaches publication

## [The Commission reviewed its AI list. Therapy chatbots are the problem it couldn’t classify.](https://adamleonsmith.substack.com/p/the-commission-reviewed-its-prohibited)

_2026-05-29 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

Self-help therapy chatbots are flagged for monitoring.

## [First EU AI Act cases in front of the courts](https://adamleonsmith.substack.com/p/first-eu-ai-act-cases-in-front-of)

_2026-05-25 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

C-806/24 and C-245/25 are the first cases at the CJEU. Here’s what the judges will be deciding.

## [A general intended purpose includes all high risk use cases by default](https://adamleonsmith.substack.com/p/a-general-intended-purpose-includes)

_2026-05-21 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

The Commission’s guidance on high-risk classification dropped consequential clarification on intended purpose.

## [James Gealy On AI Safety Standards For Frontier Models](https://adamleonsmith.substack.com/p/james-gealy-on-ai-safety-standards-2e7)

_2026-05-20 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

In this episode, hosts Michael Mainelli and Adam Leon Smith welcome James Gealy, Standardization Lead at Safer AI, a French NGO focused on AI risk modelling.

[Listen](https://api.substack.com/feed/podcast/198592137/0013549d75086f9a2f6a978b84326a52.mp3)

## [The Standard that watches the watcher](https://adamleonsmith.substack.com/p/the-standard-that-watches-the-watcher)

_2026-05-20 · Enrico PANAI · AI regulation, standards and reality_

ISO/IEC DIS 25029 and the governance of AI-enhanced nudging

## [Stream Torrents and IPTV Instantly (Sponsored)](https://crawlproof.com/a/a1yPUhsvzYZY)

_2026-05-20 · **Sponsored**_

Search, index, and play music, movies, books, and live TV in your browser.

## [The pace is picking up - JTC 21 Timeline Update – May 2026](https://adamleonsmith.substack.com/p/the-pace-is-picking-up-jtc-21-timeline)

_2026-05-15 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

More than half of the standards responding to the EU AI Act are now in public enquiry, or later in the process.

## [prEN 18282 heads to Enquiry: Cybersecurity specifications for AI Systems](https://adamleonsmith.substack.com/p/pren-18282-heads-to-enquiry-cybersecurity)

_2026-05-08 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

The latest harmonised standard to go to public enquiry supports compliance with Article 15

## [What was actually agreed in the Omnibus and what does it mean?](https://adamleonsmith.substack.com/p/what-was-actually-agreed-in-the-omnibus)

_2026-05-07 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

Analysis of the full leaked compromise

## [prEN 18228 heads to Enquiry: the product-safety answer to AI risk management](https://adamleonsmith.substack.com/p/pren-18228-heads-to-enquiry-the-product)

_2026-05-07 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

The draft harmonised standard on AI risk management has reached the CEN Enquiry stage. Here’s what practitioners should notice about how it defines risk, what counts as a risk control, and what to do

## [Mike Thieme On Making AI Standards Work For Busy Professionals](https://adamleonsmith.substack.com/p/mike-thieme-on-making-ai-standards-1a5)

_2026-05-06 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

In this episode, hosts Michael Mainelli and Adam Leon Smith welcome Mike Thieme, Managing Director and Cloud Advisory Lead at Accenture.

[Listen](https://api.substack.com/feed/podcast/198592138/00e20770ea14f64d911b192438a771a4.mp3)

## [ISO/IEC 25059 gets a rewrite: AI quality models expand beyond the product](https://adamleonsmith.substack.com/p/isoiec-25059-gets-a-rewrite-ai-quality)

_2026-05-04 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

The SQuaRE quality model for AI systems revision completes enquiry

## [AI Agents Under EU Law: what providers actually have to do](https://adamleonsmith.substack.com/p/ai-agents-under-eu-law-what-providers)

_2026-05-02 · Adam Leon Smith DEng FBCS · AI regulation, standards and reality_

High-risk agentic systems with untraceable behavioural drift cannot currently satisfy the essential requirements of the AI Act

## [Portuguese toolkit materials](https://www.iso27001security.com/post/portuguese-toolkit-materials)

_2026-04-22 · Gary Hinson · ISO27001security_

Graças a Filipe Nicacio, agora oferecemos traduções para português brasileiro de alguns materiais do ISO27k Toolkit. Pedimos desculpas por eventuais erros: não consigo revisá-los, pois a única palavra em português que sei é "Obrigado!"... e meu sotaque é péssimo! \[Courtesy of Filipe Nicacio, we now offer Brazilian Portuguese translations of some of the ISO27k Toolkit materials. Sorry about any…

## [Losing faith in ISO27k](https://www.iso27001security.com/post/losing-faith-in-iso27k)

_2026-04-16 · Gary Hinson · ISO27001security_

ISO/IEC 27002 - a generic catalogue of commonplace information security controls - expands substantially on Annex A of ISO/IEC 27001. Each of the 93 single-sentence control statements in Annex A merits about a page of more detailed explanation and guidance in '27002 ... but those details mean more work for ISO/IEC JTC 1/SC27 to maintain the standard. The committee is forever chasing after changes…

## [AI security standard at FDIS](https://www.iso27001security.com/post/ai-security-standard-at-fdis)

_2026-02-19 · Gary Hinson · ISO27001security_

Having now reached F inal D raft I nternational S tandard stage, ISO/IEC 27090 " Guidance for addressing security threats and compromises to artificial intelligence systems " is on-track for publication later this year, hopefully. This is a timely standard, giving the explosion of AI-with-everything at the moment. Hopefully it will prompt smart (and not-so-smart!) organisations to think carefully…

## [Make any domain metal (Sponsored)](https://crawlproof.com/a/aVp0iY6M0TDj)

_2026-02-19 · **Sponsored**_

Turn any domain into a blacked-out metal landing page with an email waitlist

## [ISO/IEC 27565 published](https://www.iso27001security.com/post/iso-iec-27565-published)

_2026-02-16 · Gary Hinson · ISO27001security_

ISO/IEC 27565:2026 is a brand new ISO27k standard on Z ero- K nowledge P roofs. It explains how to go about collecting and verifying personal information for various legitimate purposes without 'over-collecting' i.e. requiring and gathering additional information beyond that strictly needed for the stated purpose - verifying whether a statement or claim is or is not true. Age verification is a…

## [12 \<\< 5555](https://www.iso27001security.com/post/12-5555)

_2026-02-16 · Gary Hinson · ISO27001security_

In part, the current (fifth, 2018) edition of ISO/IEC 27000 defines key terms of art used throughout the ISO27k standards . The standard is available as a legitimate free download from ISO . If you haven't already seen it, go ahead - download the standard for a good look at these 77 terms defined in clause 3: access control attack audit audit scope authentication authenticity availability base…

## [ISO/IEC TS 27103 published](https://www.iso27001security.com/post/iso-iec-ts-27103-published)

_2026-02-09 · Gary Hinson · ISO27001security_

Cover page ISO/IEC TS 27103:2026 "Cybersecurity - Guidance on using ISO and IEC standards in a cybersecurity framework" is, essentially, a mapping of NIST's C yber S ecurity F ramework to ISO27k and other standards. The Technical Specification belatedly updates references to various clauses in the 2022 editions of ISO/IEC 27001 and 27002 from 2018's T echnical R eport. Read more about the standard…

## [Painting the Forth bridge](https://www.iso27001security.com/post/painting-the-forth-bridge)

_2026-02-02 · Gary Hinson · ISO27001security_

Although ISO/IEC 27000 and most other standards incorporate definitions, the language is often formalised/stilted and very succinct. Being the product of committees within the larger structure of the global standards bodies means new terms have to be carefully word-crafted to avoid conflict with the existing body of knowledge. Reducing definitions to their essence may be worthwhile from an…

## [Two new ISO27k projects: ISMS guidance for the neglected mediums and the SME dilemma](https://www.iso27001security.com/post/two-new-iso27k-projects-isms-guidance-for-the-neglected-mediums-and-the-sme-dilemma)

_2026-01-22 · Gary Hinson · ISO27001security_

No, not that kind of 'medium'! Two new ISO/IEC JTC 1/SC 27/WG 1 standards projects are under way, raising fundamental questions about how we standardise and promote information security. 1. Practical ISMS implementation guidance First, we are defining the scope and plan for a second part to ISO/IEC 27003 (possibly a distinct standard or some other format). This project aims to offer ISMS…

## [Cyber-insurance standard update](https://www.iso27001security.com/post/cyber-insurance-standard-update)

_2026-01-16 · Gary Hinson · ISO27001security_

I've received the first W orking D raft for the revision of ISO/IEC 27102 :2019 - "Information security management - Guidelines for cyber-insurance ". With a new title already approved ("Information security, cybersecurity and privacy protection — Guidelines for applying ISO/IEC 27001 and related standards in support of cyber insurance ") and a revised scope, the committee intends to refocus the…

## [What next?](https://www.iso27001security.com/post/what-next)

_2026-01-15 · Gary Hinson · ISO27001security_

I fixed a curious issue with page navigation today. If we open any of the detailed pages on the ISO27k standards, there are 2 sets of 3 buttons, top and bottom of the page, making it easy to navigate to the previous page (the detailed page for the next lower numbered ISO27k standard), the next page (the next higher numbered one) , or to go 'up' to the list of ISO27k standards. In testing, they all…

## [Minor site updates](https://www.iso27001security.com/post/minor-site-updates)

_2026-01-05 · Gary Hinson · ISO27001security_

Today I updated several pages concerning the current status of various ISO27k standards development projects - nothing particularly significant. I am struggling to keep up with the work of ISO/IEC JTC 1/SC 27 Working Group 5. I'm not sure at the moment whether I am not receiving WG5 emails with updates, or not reading them properly and taking note of them. Either way, it is hard for me to keep…

## [That risky Annex A](https://www.iso27001security.com/post/that-risky-annex-a)

_2026-01-02 · Gary Hinson · ISO27001security_

Having seen yet another comment on social media this morning along the lines of "I'm petrified that the certification auditor will raise a nonconformity if we don't adopt specific Annex A controls", I've added an ISO27k FAQ under the assurance section . This is one of the most frequent of F requently A sked Q uestions, a frustratingly persistent concern relating to the natural anxieties about…

## [Stakeholding adversaries](https://www.iso27001security.com/post/stakeholding-adversaries)

_2025-12-22 · Gary Hinson · ISO27001security_

I'm intrigued by the notion of 'adversaries' being classed and treated as 'stakeholders' for risk management purposes. Adversaries' interests, concerns, requirements and expectations are (on the whole) diametrically opposed to the organisation's and its more conventional stakeholders. However, as with all stakeholders ( e.g . owners, workers, partners, suppliers, customers, authorities,…

## [ISO 27799 updated - health infosec controls](https://www.iso27001security.com/post/iso-17799-updated-health-infosec)

_2025-12-18 · Gary Hinson · ISO27001security_

ISO/TC 215 has updated ISO 27799 to reflect ISO/IEC 27002:2022 , omitting the previous edition's content re ISO/IEC 27001 . The standard now concentrates on the implementation of organisational, people, physical and technological controls within the healthcare industry.

