ISO/IEC 27001, part of the growing ISO/IEC 27000 family of standards, is an Information Security Management System (ISMS) standard published in October 2005 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Its full name is ISO/IEC 27001:2005 - Information technology -- Security techniques -- Information security management systems -- Requirements but it is commonly known as "ISO 27001".

ISO/IEC 27001 formally specifies a management system that is intended to bring information security under explicit management control. Being a formal specification means that it mandates specific requirements. Organizations that claim to have adopted ISO/IEC 27001 can therefore be formally audited and certified compliant with the standard (more below).

Most organizations have a number of information security controls. Without an ISMS however, the controls tend to be somewhat disorganized and disjointed, having been implemented often as point solutions to specific situations or simply as a matter of convention. Maturity models typically refer to this stage as "ad hoc". The security controls in operation typically address certain aspects of IT or data security, specifically, leaving non-IT information assets (such as paperwork and proprietary knowledge) less well protected on the whole. Business continuity planning and physical security, for examples, may be managed quite independently of IT or information security while Human Resources practices may make little reference to the need to define and assign information security roles and responsibilities throughout the organization.
Share
Related Documents
  1. Information Security Management System (1551)
  2. ISO 27001 Intro (934)
  3. How much ISO 15504 applies to Software testing? (1249)
  4. ISO Fundamentals (930)
  5. ISO Fundamentals (835)
  6. Any standards related with ISO 9000 or 9001 for testing? (980)
  7. [Ebook] Black Books for Developer and Tester (1181)
  8. Concept of Quality Measurement System Software Based on Standard ISO 9126 and ISO 19011 (482)
  9. Quality Management System Procedures (1261)
  10. Software Quality Standards (2519)
  11. MoProSoft®: A Software Process Model for Small Enterprises (2167)
  12. ISO17025 (Quality Manual) (1105)
  13. Improving Software Quality – a benchmarking approach (1159)
  14. ISO Standards (1373)
  15. ISO29119 News !! (1003)
  16. ISO 27001 (Information Security Techniques) (1257)
  17. ISO 27002 Code of practice of ISMS (983)
  18. ISO 9001 : Quality Management System Manual (1653)
  19. What is SEI? CMM? CMMI? ISO? IEEE? ANSI? (911)
  20. Quality Management System Manual - ISO 9001:2008 (1954)