• Become a Fan!
  • Follow On Twitter
    • Subcribe to Our SMS Channel

    ISO 27001

    Posted In Tech Writing - By Sudipa Sarkar On Monday, January 12th, 2009 With 2 Comments
      



    What is ISO 27001?

    ISO 27001 is an internationally recognized structured methodology dedicated to information security. It is a standard which defines define Information Security Management System (ISMS) covering all the facets of information security namely people, process and technology.

    It is the specification for an ISMS, an Information Security Management System. BS7799 itself was a long standing standard, first published in the nineties as a code of practice. As this matured, a second part emerged to cover management systems. It is this against which certification is granted. Today in excess of a thousand certificates are in place, across the world.

    ISO 27001 enhanced the content of BS7799-2 and harmonized it with other standards. A scheme has been introduced by various certification bodies for conversion from BS7799 certification to ISO27001 certification.

    The objective of the standard itself is to “provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an Information Security Management System”. Regarding its adoption, this should be a strategic decision. Further, “The design and implementation of an organization’s ISMS is influenced by their needs and objectives, security requirements, the process employed and the size and structure of the organization”.

    The standard defines its ‘process approach’ as “The application of a system of processes within an organization, together with the identification and interactions of these processes, and their management”. It employs the PDCA, Plan-Do-Check-Act model to structure the processes, and reflects the principles set out in the OECG guidelines

    -NKJ

     tech writing  ISO 27001

    Sudipa Sarkar

    Sudipa is professional content writer, working in an MNC. She also writes professional resumes for a leading resume writer company in India. Her expertise are both technical and general contents.

    Tags:
    • iso27001documentation

      Good informative article for ISO 27001 documents and i would like to explain that ISO 17799-2000 Information Security Management Certification is also Beneficial for organization

    • http://nitinkumarjain.in Nitin Kumar Jain

      Thank you and you are absolutely right, it is beneficial for organisations.