.
ISO 27001
The goal of ISO 27001:2005 is to provide a common base for developing organizational information security policies and procedures. This standard can be used by any organization, institution or a company which uses internal or external computer systems/ possesses, depends on information technology to carry out its business activities, or simply wishes to adopt information security.
ISO 27001 part of a growing family of ISO standards, the 'ISO 27000 series is an information security management system (ISMS) standard published in October 2005 by the International Organization for Standardization (ISO).
Its full name is ISO/IEC 27001:2005 - Information technology -- Security techniques -- Information security management systems -- Requirements but it is commonly known as "ISO 27001".
The objective of the standard itself is to "provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an Information Security Management System
It is intended to be used in conjunction with ISO 27002, the Code of Practice for Information Security Management, which lists security control objectives and recommends a range of specific security controls. Organizations that implement an ISMS in accordance with the best practice advice in ISO27002 are likely simultaneously to meet the requirements of ISO 27001 but certification is entirely optional (unless mandated by the organization's stakeholders).
ISO 27001 is suitable for all those organization where the protection of information is critical, such as in the IT sector, BPO, finance, health. Irrespective to size, location of the organization. it can be used to assure customers that their information is being protected.
Three ISO2700 standards are already available:
· ISO 27001: The Information Security Management System certification standard;
· ISO 27002: The code of practice for information security management with advice on a broad range of controls;
· ISO 27006:, a guide to the ISMS certification process for certification bodies.
THE CONTENTS OF ISO 27001
The content sections of the standard are:
· Management Responsibility
· Internal Audits
· ISMS Improvement
· Annex A - Control objectives and controls
· Annex B - OECD principles and this international standard
· Annex C - Correspondence between ISO 9001, ISO 14001 and this standard
Benefits of ISO 27001:2005:
· Systematic identification of Information Security Risks and its mitigation.
· Availability of Business Continuity Plans in case of manmade and natural disasters.
· Potentially lower premium of computer risk insurance.
· Better protection of confidential data and reduced risks from hackers’ attacks.
· Faster and easier recovery from the attacks and improved ability to survive disasters.
· Compliance with legal and contractual requirements.
· A structured and globally recognized Information Security Methodology.
For more information contact:
|
|
|
|