JA slide show
 
What is ISO/IEC 27001?

The ISO/IEC 27001 standard was published in October 2005, essentially as a replacement for the old BS7799-2 standard. ISO 27001 is the specification for an ISMS, an Information Security Management System. The BS7799 standard was a long-standing standard, first published in the nineties as a code of practice. As this matured, a second part emerged to cover management systems - and this is what certification is granted against. Thousands of certificates are in place today, all around the world.

ISO/IEC 27001 enhanced the content of BS7799-2 and harmonized it with other standards. A program has been introduced by various certification bodies for upgrading from BS7799 certification to ISO/IEC 27001 certification.

 

The Objective of ISO/IEC 27001

The objective of the standard itself is to be a model for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an Information Security Management System. Regarding its adoption, this should be a strategic decision. Moreover, "the design and implementation of an organization's ISMS is influenced by its needs and objectives, security requirements, the process employed and the size and structure of the organization".

The ISO/IEC 27001 standard defines its 'process approach' as "The application of a system of processes within an organization, together with the identification and interactions of these processes, and their management". ISO 27001 employs the PDCA (Plan-Do-Check-Act) model to structure the processes and reflects the principles set out in the OECD guidelines (see oecd.org).

 

Webinar

Learn more about RM STUDIO. Request a Webinar with one of our experts.

Overview of RM STUDIO

Are you ready? Get a quick overview of RM STUDIO.

RM Studio Brochure

Download the latest version of our RM STUDIO brochure.

Benefits of RM Studio

RM studio is simple and easy to use. The software guides the user through each step of the risk assessment process, ensuring that all aspects of the risk assessment process are covered.

Risk assessment

Risk Assessment plays an important role in the implementation of information security and is one of the requirements.

Information Assets

Information asset is any information of value to a company and its operation. Information assets, like any other assets of a company.

Traceability

Offering traceability is a very important feature in software. Data traceability is a key component in RM Studio®