Sponsored ads:
Information security Standards:
The standard "established guidelines and general principles for initiating, implementing, maintaining, and improving information security management within an organization".
The actual controls listed in the standard are intended to address the specific requirements identified via a formal risk assessment.
The standard is also intended to provide a guide for the development of "organizational security standards and effective security management practices and to help build confidence in inter-organizational activities.
ISO/IEC 17799:2005 establishes guidelines and general principles for initiating, implementing, maintaining, and improving information security management
ISO/IEC 27001:2005 is designed to ensure the selection of adequate and proportionate security controls that protect information assets and give confidence
ISO/IEC 27001 is the only auditable international standard which defines the requirements for an Information Security Management System (ISMS)
|