Wednesday, April 27, 2011

ISO and IEC help beef up information security management systems

ISO and IEC have added to their toolbox of information security standards, with guidance for the successful design and implementation of ISO/IEC 27001:2005.

IT securityISO/IEC 27003:2010, Information technology – Security techniques – Information security management system implementation guidance, gives advice that will be useful for all types of security-conscious organizations, regardless of their size, complexity and risks.

Today, information security is constantly in the news with identity theft, breaches in corporate financial records and threats of cyber terrorism. An information security management system (ISMS) is a systematic approach to managing sensitive company information so that it remains secure. It encompasses people, processes and IT systems.

The successful design and implementation of an ISMS (ISO/IEC 27001:2005) will reassure customers and suppliers that information security is taken seriously within the organizations they deal with because they have in place state-of-the-art processes to deal with information security threats and issues.

Prof. Edward Humphreys, Convenor of the working group, which developed the new standard, comments: "By using ISO/IEC 27003:2010, the organization will be able to develop a process for information security management, giving stakeholders the assurance that risks to information assets are continuously maintained within acceptable information security bounds as defined by the organization."

ISOIEC 27003:2010 covers the process of ISMS specification and design, from inception to the production of implementation plans. It provides guidance on how to obtain management approval, and gives the concepts on how to design and plan the ISMS project to ensure its successful implementation.

ISO/IEC 27003:2010 is intended to be used in conjunction with ISO/IEC 27001:2005 and ISO/IEC 27002:2005. It is not intended to modify and/or reduce the requirements specified in either.

4 comments:

  1. ISO 27001 It is not a technical standard that would describe the ISMS into technical detail It does not focus only on information technology, but also on other important assets at the organization.

    ISO 27001

    ReplyDelete
  2. Nice information that ISO and IEC help beef up information security management systems providing in your blog. security training consultancy. Thanks for nice post...

    ReplyDelete
  3. Thanks for the sharing information about ISO 27001 standard, it was awesome post. I believe that this information helps in implementation of ISO 27001 Download for information security management system and iso 27001 certification.

    ReplyDelete
  4. nice blog !! i was looking for blogs related of iso consultants . then i found this blog, this is really nice and interested to read.

    ReplyDelete