What is ISO/IEC 27001?
ISO/IEC 27001 is an international standard for an Information Security Management System (ISMS). The ISMS
provides assurance of adequate security controls over information assets. ISO/IEC 27001 has evolved from British
Standard BS 7799-2. Organizations can be certified against ISO/IEC 27001. ISO/IEC 27001 is related to ISO/IEC 17799.
Domain
|
Specifications
|
Best Practices
|
Process Model
|
Maturity Model
|
Information Security Management Systems
|
yes
|
no
|
no
|
no
|
ISO/IEC 27001 consists of one document:
-
ISO/IEC 27001-1: Information security management systems -- Requirements
This document can be purchased from the http://www.iso.org/.
ISO/IEC 27001 describes 133 specific controls, categorized into 39 control objectives, listed in 11 distinct chapters
of ISO 17799. These controls were directly derived from those listed in ISO/IEC 17799.
Process Mapping
A.5. Security Policy
A.6. Organization of Information Security
A.7.1 Protect organizational assets
A.8. Human Resources Security
A.9. Physical and Environmental Security
A.10. Communications and Operations Management
A.11. Access Control
A.12. Information Systems Acquisition, Development and Maintenance
A.13. Information Security Incident Management
A.14. Business Continuity Management
ISO/IEC 27001 Controls
|
PRM-IT Process(es)
|
Specific Activity or Activities
|
A.14.1 Reduce effects of major failures or disasters to business processes
|
IT Service Continuity Management
|
all
|
A.15. Compliance
|