Subject
Information security is defined as preservation of confidentiality, integrity and availability of information (ISO/IEC 27000), while:
- confidentiality is a property that information is not made available or disclosed to unauthorized individuals, entities, or processes
- integrity is a property of accuracy and completeness
- availability is a property of being accessible and usable on demand by an authorized entity
Applied standards
ISO/IEC 27001 provides requirements for establishing, implementing, maintaining and continually improving an information security management system. The adoption of an information security management system is a strategic decision for an organization. The establishment and implementation of an organization’s information security management system is influenced by the organization’s needs and objectives, security requirements, the organizational processes used and the size and structure of the organization. All of these influencing factors are expected to change over time.
The information security management system preserves the confidentiality, integrity and availability of information by applying a risk management process and gives confidence to interested parties that risks are adequately managed.
It is important that the information security management system is part of and integrated with the organization’s processes and overall management structure and that information security is considered in the design of processes, information systems, and controls. It is expected that an information security management system implementation will be scaled in accordance with the needs of the organization.
This document can be used by internal and external parties to assess the organization’s ability to meet the organization’s own information security requirements.
The order in which requirements are presented in this document does not reflect their importance or imply the order in which they are to be implemented. The list items are enumerated for reference purpose only.
Our services
The SSA is planning to provides high quality services of Certification of information security management system based on ISO/IEC 27001. The service will include a complex of onsite and off-site assessment of how organisation established, implemented, maintained and continually improved an information security management system.
Links
- ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems – Requirements
- ISO/IEC 27001:2022/Amd 1:2024 Information security, cybersecurity and privacy protection - Information security management systems - Requirements - Amendment 1: Climate action changes
- ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection - Guidance on managing information security risks
- ISO/IEC 27701:2019 Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelines
- ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection - Information security controls
- ISO/IEC 27019:2017 Information technology - Security techniques - Information security controls for the energy utility industry