ISO 27001
Home > Information Security Definitions - ISO 27001
SearchSecurity.co.UK Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

ISO 27001


Show me everything on IT Security Frameworks and Standards

DEFINITION - What is ISO 27001?

ISO 27001 (formally known as ISO/IEC 27001:2005) is a specification for an information security management system (ISMS). An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes.

According to its documentation, ISO 27001 was developed to "provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an information security management system."

ISO 27001 uses a topdown, risk-based approach and is technology-neutral. The specification defines a six-part planning process:

  1. Define a security policy.
  2. Define the scope of the ISMS.
  3. Conduct a risk assessment.
  4. Manage identified risks.
  5. Select control objectives and controls to be implemented.
  6. Prepare a statement of applicability.

The specification includes details for documentation, management responsibility, internal audits, continual improvement, and corrective and preventive action. The standard requires cooperation among all sections of an organisation.

The 27001 standard does not mandate specific information security controls, but it provides a checklist of controls that should be considered in the accompanying code of practice, ISO/IEC 27002:2005. This second standard describes a comprehensive set of information security control objectives and a set of generally accepted good practice security controls.

ISO 27002 contains 12 main sections:

1. Risk assessment
2. Security policy
3. Organization of information security
4. Asset management
5. Human resources security
6. Physical and environmental security
7. Communications and operations management
8. Access control
9. Information systems acquisition, development and maintenance
10. Information security incident management
11. Business continuity management
12. Compliance

Organisations are required to apply these controls appropriately in line with their specific risks. Third-party accredited certification is recommended for ISO 27001 conformance.

Other standards being developed in the 27000 family are:

  • 27003 – implementation guidance.
  • 27004 - an information security management measurement standard suggesting metrics to help improve the effectiveness of an ISMS.
  • 27005 – an information security risk management standard. (Published in 2008)
  • 27006 - a guide to the certification or registration process for accredited ISMS certification or registration bodies. (Published in 2007)
  • 27007 – ISMS auditing guideline.

Learn more about IT Security Frameworks and Standards
Benefits of ISO 27001 and ISO 27002 certification for your enterprise: If your enterprise is considering becoming ISO 27001 and 27002 certified, there are several important questions to ask.
How to migrate from SAS 70 to ISO 27001: What would it take to migrate to the ISO 27001 certification from SAS70?
Regulatory Compliance and ISO 27001: In this excerpt from "The Case for ISO 27001," author Alan Calder explains how infosec pros can use ISO 27001 to comply with complex and overlapping regulatory requirements.
Management Support: In the excerpt from "Nine Steps to ISO 27001 Success: An Implementation Overview," Alan Calder explains the first key to ISO 27001 success and what it takes to set up for success.
Some Things SOX Doesn't Say: SOX Myths: In this excerpt from Chapter 1 of "Sarbanes-Oxley for Dummies," author Jill Gilbert Welytok demystifies four common myths about SOX.
How to develop a culture of security in the enterprise: Michael Cobb reviews how one government maturity model contains guidance that can help your business establish strong security training practices and create a culture of security.
Benefits of ISO 27001 and ISO 27002 certification for your enterprise: If your enterprise is considering becoming ISO 27001 and 27002 certified, there are several important questions to ask.

LAST UPDATED: 24 Mar 2009

Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com





FILE EXTENSION AND FILE FORMAT LIST
File Extension and File Format List:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #


RELATED CONTENT
How to develop a culture of security in the enterprise
Michael Cobb reviews how one government maturity model contains guidance that can help your business establish strong security training practices and...
ICO issues draft guidelines for personal information online
The Information Commissioner's Office has issued guidelines for companies who gather personal information online as part of their everyday work.
Using a privacy impact assessment template for DPA compliance
Personal information management remains a critical enterprise task. One standard originally used for government data can help your organisation assess...

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Financial Services Authority  (SearchSecurityUK.com)
The FSA (Financial Services Authority) is an independent, non-governmental body that regulates the financial services industry in the UK, including...
IISP (Institute of Information Security Professionals)  (SearchSecurityUK.com)
The IISP (Institute of Information Security Professionals) is a London-based professional membership association who describes its purpose as: "to...




UK Whitepapers & Research - ISO 27001 Solutions
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts