ISO 27001
Home > Information Security Definitions - ISO 27001
SearchSecurity.co.UK Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

ISO 27001


Show me everything on IT Security Frameworks and Standards

DEFINITION - What is ISO 27001?

ISO 27001 (formally known as ISO/IEC 27001:2005) is a specification for an information security management system (ISMS). An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes.

According to its documentation, ISO 27001 was developed to "provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an information security management system."

ISO 27001 uses a topdown, risk-based approach and is technology-neutral. The specification defines a six-part planning process:

  1. Define a security policy.
  2. Define the scope of the ISMS.
  3. Conduct a risk assessment.
  4. Manage identified risks.
  5. Select control objectives and controls to be implemented.
  6. Prepare a statement of applicability.

The specification includes details for documentation, management responsibility, internal audits, continual improvement, and corrective and preventive action. The standard requires cooperation among all sections of an organisation.

The 27001 standard does not mandate specific information security controls, but it provides a checklist of controls that should be considered in the accompanying code of practice, ISO/IEC 27002:2005. This second standard describes a comprehensive set of information security control objectives and a set of generally accepted good practice security controls.

ISO 27002 contains 12 main sections:

1. Risk assessment
2. Security policy
3. Organization of information security
4. Asset management
5. Human resources security
6. Physical and environmental security
7. Communications and operations management
8. Access control
9. Information systems acquisition, development and maintenance
10. Information security incident management
11. Business continuity management
12. Compliance

Organisations are required to apply these controls appropriately in line with their specific risks. Third-party accredited certification is recommended for ISO 27001 conformance.

Other standards being developed in the 27000 family are:

  • 27003 – implementation guidance.
  • 27004 - an information security management measurement standard suggesting metrics to help improve the effectiveness of an ISMS.
  • 27005 – an information security risk management standard. (Published in 2008)
  • 27006 - a guide to the certification or registration process for accredited ISMS certification or registration bodies. (Published in 2007)
  • 27007 – ISMS auditing guideline.

Learn more about IT Security Frameworks and Standards
Benefits of ISO 27001 and ISO 27002 certification for your enterprise: If your enterprise is considering becoming ISO 27001 and 27002 certified, there are several important questions to ask.
Regulatory Compliance and ISO 27001: In this excerpt from "The Case for ISO 27001," author Alan Calder explains how infosec pros can use ISO 27001 to comply with complex and overlapping regulatory requirements.
ISO 27001 could bridge the regulatory divide, expert says: Former Microsoft CISO Karen Worstell explains how ISO 27001 can help companies comply with a variety of regulations and standards.
PCI compliance UK: The future of European merchant PCI compliance: This PCI DSS UK compliance guide offers advice on how to achieve merchant PCI compliance with expert advice and real-world case studies.
Some Things SOX Doesn't Say: SOX Myths: In this excerpt from Chapter 1 of "Sarbanes-Oxley for Dummies," author Jill Gilbert Welytok demystifies four common myths about SOX.
ISO 27001 SoA: Creating an information security policy document: In this expert tip, learn the importance of creating a Statement of Applicability (SoA), crucial to ISO 27001 compliance.
How to develop a culture of security in the enterprise: Michael Cobb reviews how one government maturity model contains guidance that can help your business establish strong security training practices and create a culture of security.
Using ICO privacy impact assessment template for DPA compliance: Personal information management remains a critical enterprise task. One standard originally used for government data can help your organisation assess its own privacy risks.

LAST UPDATED: 24 Mar 2009

Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com





FILE EXTENSION AND FILE FORMAT LIST
File Extension and File Format List:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #


RELATED CONTENT
ISACA issues mobile smartphone security policy guidance
ISACA recently issued new guidance, warning users of the dangers of smartphones, and giving guidance on creating a policy for their secure use.
How to meet the PCI DSS compliance deadline on an IT security budget
Learn how to meet the upcoming PCI DSS compliance deadline while sticking to an IT security budget by leveraging existing security infrastructure in...
PCI compliance UK: The future of European merchant PCI compliance
This PCI DSS UK compliance guide offers advice on how to achieve merchant PCI compliance with expert advice and real-world case studies.

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Financial Services Authority  (SearchSecurityUK.com)
The FSA (Financial Services Authority) is an independent, non-governmental body that regulates the financial services industry in the UK, including...
IISP (Institute of Information Security Professionals)  (SearchSecurityUK.com)
The IISP (Institute of Information Security Professionals) is a London-based professional membership association who describes its purpose as: "to...








UK Whitepapers & Research - ISO 27001 Solutions
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Terms of Use | Read our Privacy Policy
  TechTarget