Misplaced Pages

ISO/IEC 27000

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.
(Redirected from ISO 27000) This article is about the individual 27000 standard. For the family of standards, see ISO/IEC 27000 family. Information security management system standard
This article relies excessively on references to primary sources. Please improve this article by adding secondary or tertiary sources.
Find sources: "ISO/IEC 27000" – news · newspapers · books · scholar · JSTOR (April 2017) (Learn how and when to remove this message)

ISO/IEC 27000 is one of the standards in the ISO/IEC 27000 series of information security management systems (ISMS)-related standards. The formal title for ISO/IEC 27000 is Information technology — Security techniques — Information security management systems — Overview and vocabulary.

The standard was developed by subcommittee 27 (SC27) of the first Joint Technical Committee (JTC1) of the International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC).

ISO/IEC 27000 provides:

  • An overview of, and introduction to, the entire ISO/IEC 27000 series.
  • A formally-defined glossary or vocabulary of the specialist terms used throughout the ISO/IEC 27000 series.

ISO/IEC 27000 is available for free via the ITTF website.

Overview and introduction

The standard describes the purpose of an ISMS, a management system similar in concept to those recommended by other ISO standards such as ISO 9000 and ISO 14000, used to manage information security risks and controls within an organization. Bringing information security deliberately under overt management control is a central principle throughout the ISO/IEC 27000 series of standards.

The target audience is users of the remaining ISO/IEC 27000-series information security management standards.

Glossary

Information security, like many technical subjects, is evolving a complex web of terminology. Relatively few authors take the trouble to define precisely what they mean, an approach which is unacceptable in the standards arena as it potentially leads to confusion and devalues formal assessment and certification. As with ISO 9000 and ISO 14000, the base '000' standard is intended to address this.

See also

References

  1. ISO/IEC 27000:2016
  2. "Publicly Available Standards". ISO. Retrieved 22 July 2024.
ISO standards by standard number
List of ISO standardsISO romanizationsIEC standards
1–9999
10000–19999
20000–29999
30000+
IEC standards
IEC
ISO/IEC
Related
Stub icon

This computer security article is a stub. You can help Misplaced Pages by expanding it.

Stub icon

This standards- or measurement-related article is a stub. You can help Misplaced Pages by expanding it.

Categories: