to add a new content
Resource
ISO/IEC 27004:2016 IT Security Techniques — Information Security Management — Monitoring, Measurement, Analysis and Evaluation

ISO (the International Organisation for Standardisation) and IEC (the International Electrotechnical Commission) form the specialised system for worldwide standardisation. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organisation to deal with particular fields of technical activity. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.

This international standard was created to help organisations evaluate the information security performance and the effectiveness of an information security management system. The results of monitoring and measurement of an information security management system (ISMS) can be supportive of decisions relating to ISMS governance, management, operational effectiveness and continual improvement. It also helps to establish

  1. the monitoring and measurement of information security performance

  2. the monitoring and measurement of the effectiveness of an information security management system (ISMS) including its processes and controls

  3. the analysis and evaluation of the results of monitoring and measurement.

Published 01/01/2016
Authoring body: International Organisation for Standardisation (ISO)
Standards
Resource
ISO 22301:2019 Security and Resilience — Business Continuity Management Systems — Requirements

ISO (the International Organisation for Standardisation) and IEC (the International Electrotechnical Commission) form the specialised system for worldwide standardisation. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organisation to deal with particular fields of technical activity. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.

This standard speaks into  the structure and requirements for implementing and maintaining a business continuity management system (BCMS) that develops business continuity within an organisation experience disruption.

A BCMS emphasises the importance of:

  • understanding the organisation’s needs and the necessity for establishing business continuity policies and objectives;

  • operating and maintaining processes, capabilities and response structures for ensuring the organisation will survive disruptions;

  • monitoring and reviewing the performance and effectiveness of the BCMS;

  • continual improvement based on qualitative and quantitative measures.

The purpose of a BCMS is to prepare for, provide and maintain controls and capabilities for managing an organisation’s overall ability to continue to operate during disruptions.

  • supporting its strategic objectives

  • creating a competitive advantage

  • protecting and enhancing its reputation and credibility

  • reducing legal and financial exposure

  • reducing direct and indirect costs of disruptions

  • protecting life, property and the environment

  • providing confidence in the organisation’s ability to succeed

  • improving its capability to remain effective during disruptions

  • addressing operational vulnerabilities

The management process of BCMS are categorised by the following:

  • policy

  • planning

  • implementation and operation

  • performance assessment

  • management review

  • continual improvement

The outcomes of maintaining a BCMS are shaped by the organisation’s legal, regulatory, organisational and industry requirements, products and services provided, processes employed, size and structure of the organisation, and the requirements of its interested parties.

Published 01/01/2019
Authoring body: International Organisation for Standardisation (ISO)
Standards
Resource
ISO/IEC 27013:2015 IT Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1

ISO (the International Organisation for Standardisation) and IEC (the International Electrotechnical Commission) form the specialised system for worldwide standardisation. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organisation to deal with particular fields of technical activity. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.

The relationship between information security management and service management is so close that many organisations already recognise the benefits of adopting the two International Standards for these domains. There are a number of advantages in implementing an integrated management system.

Benefits:

  • Enhanced credibility, with internal and external customers

  • Lower cost of an integrated programme of two projects

  • Reduction in implementation time due to the integrated development of processes common to both standards

  • Better communication, reduced cost and improved operational efficiency through elimination of unnecessary duplication

  •  a greater understanding by service management

This International Standard is intended for use by persons with knowledge of both of the International Standards ISO/IEC 27001 (information security management system (ISMS) and ISO/IEC 20000-1 (a service management system (SMS)) and provides guidance on the implementation of both international standards.

Published 01/01/2015
Authoring body: International Organisation for Standardisation (ISO)
Standards
Resource
ISO/IEC 27001:2013 IT Security techniques — Information Security Management Systems — Requirements

ISO (the International Organisation for Standardisation) and IEC (the International Electrotechnical Commission) form the specialised system for worldwide standardisation. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organisation to deal with particular fields of technical activity. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.

The implementation of an information security management system is a strategic decision for an organisation that is influenced by the organisation’s needs and objectives, security requirements, the organisational processes and thus the International Standard has been setup to establish, implement, maintain and continually improve an information security management system.

The information security management system preserves the confidentiality, integrity and availability of information by applying a risk management process and gives confidence to interested parties that risks are adequately managed.

This International Standard specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organisation. This also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organisation and is applicable to all organisations, irrespective of size and structure.

Published 01/01/2013
Authoring body: International Organisation for Standardisation (ISO)
Standards
Resource
ISO/IEC 27000:2020 IT Security techniques - Information Security management systems - Overview & Vocabulary

The International Organisation Standardisation (ISO) and the International Electrotechnical Commission (IEC) form the specialised system for worldwide standardisation. National bodies that are apart of the ISO or IEC participate through technical committees in the development of International standards to deal with particular areas of technical activities.

ISO/IEC in light of information technology provides an international standard and overview by for management systems by which a model can be followed in setting up and operating a management system. Information Security Management System (ISMS) is responsible for ensuring continuous development of the international management system standards.

Through the various standards developed, organisations can develop and implement a framework for managing and protecting the security of the information assets and systems including financial information, intellectual property, employee details, customer, client and third parties personal details.

The ISMS Standard includes standards that define requirements for an ISMS, provides direct support and guidance for the overall process to implement and maintain an ISMS standard, address conformity assessment for ISMS and provide terms and definitions for the international standard.

Published 01/01/2020
Authoring body: International Organisation Standardisation (ISO)
Standards