BS ISO/IEC 27005:2011 PDF
Information technology. Security techniques. Information security risk management
Information technology. Security techniques. Information security risk management
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Дата публикации:
- 30 июня 2011 г.
- ICS:
- 03.100.70
- Технический комитет:
- IEC
- SKU:
- BS ISO/IEC 27005:2011
Abstract
BS ISO/IEC 27005:2011 Information security management systems – Information security risk management What is it? BS ISO/IEC 27005:2011 expands on the requirements in BS ISO/IEC 27001 for information security risk management. Conducting risk assessments and subsequently performing risk management is an essential component of any Information Security Management System (ISMS). The technical approach used within BS ISO/IEC 27005:2011 is fully aligned with the international standard for risk management, BS . How does it work? BS describes an information security risk management process and associated actions modelled on the generic risk management processes defined in BS . This information security risk management is then linked back to the risk assessment and risk management requirements of BS . Annexes provide checklists, examples and other practical advice. BS does not define or mandate any particular methodology for performing risk assessments. However, some examples of suitable approaches are given as examples in an annex. Who should buy it? Anyone who is planning to build an ISMS based on BS needs BS as well. It is an essential supporting standard for ISMS implementation. It will be useful for anyone needing insight into the practical aspects of building an ISMS. It can also be used as a stand-alone guide to performing information risk management in ways compatible with
Похожие стандарты
Стандарты, упомянутые в описании