ISO Liaison Working Group

The purpose of the OWASP ISO Liaison Working Group is to formally bridge the gap between OWASP’s practitioner-led security guidance and the International Organization for Standardization’s (ISO) global policy frameworks. While OWASP dominates the operational reality of application security, ISO standards (such as the 27000 series) drive governance and compliance.

About ISO Liaison Working Group

What the group does

ISO standards decide what auditors, regulators and procurement teams ask for, and OWASP projects decide what engineers build and test against. When the two drift apart, an organization ends up maintaining two vocabularies for one set of practices, and the standards fall behind the way software is now delivered. This working group exists to keep them aligned from the inside. Through the Foundation's liaison to ISO/IEC JTC 1/SC 27/WG 4, OWASP experts take part in drafting and reviewing application security standards, comment on committee drafts and draft international standards, and offer OWASP projects such as the ASVS, SAMM and the Top 10 as reference material where a standard needs worked examples. The group also works in the other direction, bringing what the committee is doing back to OWASP project leaders early enough for them to respond.

Where the work happens

ISO/IEC JTC 1/SC 27 is the joint ISO and IEC subcommittee for information security, cybersecurity and privacy protection, and it is the home of the ISO/IEC 27000 series. Its work is divided among five working groups: WG 1 for information security management systems, WG 2 for cryptography and security mechanisms, WG 3 for security evaluation, testing and specification, WG 4 for security controls and services, and WG 5 for identity management and privacy technologies. OWASP's liaison is with WG 4, which owns the ISO/IEC 27034 application security series and is where new application security work is proposed and drafted. The standards and work items this group follows are listed in the Standards tab; the list is taken from the public ISO programme of work and is updated as projects move through the committee's stages.

How the liaison works

A Category C liaison operates at the working group level. The Foundation nominates experts to WG 4, the experts receive the working group's documents under ISO's rules, and they take part in meetings and comment cycles alongside the national body delegations. Liaison organizations contribute technically but do not vote; ballots on committee drafts and draft international standards belong to the national bodies. Two consequences follow for how this group is run. First, working documents are confidential to the committee, so drafts are never posted here or on GitHub and only registered experts see them. Second, comments submitted through the liaison carry the name of the Foundation rather than of an individual, so every comment set is reviewed within the group before the liaison officer submits it. Anyone may join the group's discussions; the roster of nominated experts is smaller and is vetted for these reasons.

Get involved

There are three ways to take part, and they ask for different levels of commitment. Observers join the Slack channel (#iso) and participate in public surveys and provide general feedback. Participants act as experts in the space and provide critical feedback to our submissions. Leaders are nominated by the OWASP Working Group Chair, receive the committee's documents and are expected to read full drafts, attend the working group's meetings in person or remotely, and return comments within the committee's comment periods. Project leaders whose work is referenced, or could be referenced, by an ISO standard are invited to name a contact so that the group can bring committee developments to them early. To join as an observer, visit the Slack channel #iso. To be considered as a participant, fill out the contributor form from the #iso channel and submit it to the Working Group Chair. We currently provide feedback within a handful of application security and AI security standards. We would love to have you on the team!

Corporate Supporters
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.