ISO/IEC 27000, 27001 and 27002 for Information Security Management

  • Disterer G
N/ACitations
Citations of this article
872Readers
Mendeley users who have this article in their library.

Abstract

With the increasing significance of information technology, there is an urgent need for adequate measures of informa-tion security. Systematic information security management is one of most important initiatives for IT management. At least since reports about privacy and security breaches, fraudulent accounting practices, and attacks on IT systems ap-peared in public, organizations have recognized their responsibilities to safeguard physical and information assets. Se-curity standards can be used as guideline or framework to develop and maintain an adequate information security man-agement system (ISMS). The standards ISO/IEC 27000, 27001 and 27002 are international standards that are receiving growing recognition and adoption. They are referred to as " common language of organizations around the world " for information security [1]. With ISO/IEC 27001 companies can have their ISMS certified by a third-party organization and thus show their customers evidence of their security measures.

Cite

CITATION STYLE

APA

Disterer, G. (2013). ISO/IEC 27000, 27001 and 27002 for Information Security Management. Journal of Information Security, 04(02), 92–100. https://doi.org/10.4236/jis.2013.42011

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free