|
ISO 27001 This is the specification for an information security management system (an ISMS) which replaced the old BS7799-2 standard.
ISO 27002 This is the 27000 series standard number of what was originally the ISO 17799 standard (which itself was formerly known as BS7799-1).
This will be the official number of a new standard intended to offer guidance for the implementation of an ISMS (IS Management System) .
This standard covers information security system management measurement and metrics, including suggested ISO27002 aligned controls.
This is the methodology independent ISO standard for information security risk management.
This standard provides guidelines for the accreditation of organizations offering ISMS certification.
ISO/IEC 27000 is part of a growing family of ISO/IEC Information Security Management Systems (ISMS) standards, the 'ISO/IEC 27000 series'. ISO/IEC 27000 is an international standard entitled: Information technology — Security techniques — Information security management systems — Overview and vocabulary.
ISO/IEC 27000 provides:
- An overview of and introduction to the entire ISO/IEC 27000 family of Information Security Management Systems (ISMS) standards.
- A glossary or vocabulary of fundamental terms and definitions used throughout the ISO/IEC 27000 family.
Information security, like many technical subjects, is evolving a complex web of terminology. Relatively few authors take the trouble to define precisely what they mean, an approach which is unacceptable in the standards arena as it potentially leads to confusion and devalues formal assessment and certification. As with ISO 9000 and ISO 14000, the base '000' standard is intended to address this.The target audience is users of the remaining ISO/IEC 27000-series information security management standards.
|