|
|
|
| |
|
 |
|
ISO Overview
- Entitled Information technology - Security techniques - Code of practice for information security management. ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 17799:2005 and subsequently renumbered ISO/IEC 27002:2005 in July 2007
- ISO/IEC 27002 provides best practice recommendations on information security management for use by those who are responsible for initiating, implementing or maintaining Information Security Management Systems (ISMS).
- Information security is defined within the standard in the context of the C-I-A triad: the preservation of
- Confidentiality (ensuring that information is accessible only to those authorized to have access)
- Integrity (safeguarding the accuracy and completeness of information and processing methods) and
- Availability (ensuring that authorized users have access to information and associated assets when required).
|
|
Hawaii ISO/IEC 27002 17799:2005
|