|
ISO 27001 - is the new international standard for Information Security Management
System (ISMS). Replacing BS7799-2:2002, ISO/IEC 27001:2005 is the requirements specificiations that will enable businesses and organizations throughout the world
to develop a best-in-class ISMS. ISO 27001 is the first in a family of international
information security standards that will underpin and protect IT worldwide over
the next decade. ISO 27001 is designed to harmonize with ISO 9001:2000 and ISO 14001:1996
so that management systems can be effectively integrated. It implements the Plan-Do-Check-Act
(PDCA) model and reflects the principles of the 2002 OECD guidance on the security
of information systems and networks.
BS7799: is the British Standard governing information security
and management. It provides the industry approved model for an Information Security
Management System (ISMS) and addresses the Confidentiality, Integrity and Availability
of information within an organization.
ISO 17799 - International Stamdard of Information Security Management.
ISO 17799 adresses information security from a people, process, and technology perspective.
The standard describes the essential controls that must exist to ensure
both physical as well as information security.
ISO 1335 - Information Security Management and Guidelines
of the Management of IT security.
This standard provides general guidance on the
management
of IT security and provides several models that can be used to explain and implement
IT security.
|