ISO/IEC 27000-series

The ISO/IEC 27000-series (also known as the 'ISMS Family of Standards' or 'ISO27k' for short) comprises information security standards published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).[1]

The series provides best practice recommendations on information security management, risks and controls within the context of an overall information security management system (ISMS), similar in design to management systems for quality assurance (the ISO 9000 series) and environmental protection (the ISO 14000 series).

The series is deliberately broad in scope, covering more than just privacy, confidentiality and IT or technical security issues. It is applicable to organizations of all shapes and sizes. All organizations are encouraged to assess their information security risks, then implement appropriate information security controls according to their needs, using the guidance and suggestions where relevant. Given the dynamic nature of information security, the ISMS concept incorporates continuous feedback and improvement activities, summarized by Deming's "plan-do-check-act" approach, that seek to address changes in the threats, vulnerabilities or impacts of information security incidents.

The standards are the product of ISO/IEC JTC1 (Joint Technical Committee 1) SC27 (Subcommittee 27), an international body that meets in person twice a year.

The original ISO/IEC standards are sold directly by ISO, while sales outlets associated with various national standards bodies also sell various versions including local translations.

Published standards

The published standards related to "information technology - security techniques" are:

In preparation

See also

References

  1. ISO Freely Available Standards - see ISO/IEC 27000:2014
  2. http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=42106
  3. ISO/IEC 27014
  4. Mahncke, R. J. (2013). The Applicability of ISO/IEC27014:2013 For Use Within General Medical Practice.
  5. "ISO/IEC 27040". ISO Standards Catalogue. ISO. Retrieved 2014-06-15.

External links