BS ISO/IEC 27005:2011
Information technology. Security techniques. Information security risk management
Information technology. Security techniques. Information security risk management
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Дата публикации:
- 30 июня 2011 г.
- ICS:
- 03.100.70
- Технический комитет:
- IEC
- SKU:
- BS ISO/IEC 27005:2011
Abstract
BS ISO/IEC 27005:2011 Information security management systems – Information security risk management What is it? BS ISO/IEC 27005:2011 expands on the requirements in BS ISO/IEC 27001 for information security risk management. Conducting risk assessments and subsequently performing risk management is an essential component of any Information Security Management System (ISMS). The technical approach used within BS ISO/IEC 27005:2011 is fully aligned with the international standard for risk management, BS ISO 31000 . How does it work? BS ISO/IEC 27005:2011 describes an information security risk management process and associated actions modelled on the generic risk management processes defined in BS ISO 31000:2009 . This information security risk management is then linked back to the risk assessment and risk management requirements of BS ISO/IEC 27001:2005 . Annexes provide checklists, examples and other practical advice. BS ISO/IEC 27005:2011 does not define or mandate any particular methodology for performing risk assessments. However, some examples of suitable approaches are given as examples in an annex. Who should buy it? Anyone who is planning to build an ISMS based on BS ISO/IEC 27001 needs BS ISO/IEC 27005:2011 as well. It is an essential supporting standard for ISMS implementation. It will be useful for anyone needing insight into the practical aspects of building an ISO/IEC 27001 ISMS. It can also be used as a stand-alone guide to performing information risk management in ways compatible with
Похожие стандарты
Стандарты, упомянутые в описании
ISO 31000:2009
ОтменёнRisk management — Principles and guidelines
PD ISO/IEC TR 27023:2015
ДействующийInformation technology. Security techniques. Mapping the revised editions of ISO/IEC 27001 and ISO/IEC 27002
What is ISO/IEC TR 27023 - Information technology- Security techniques about? ISO/IEC TR 27023 is a security standard on information technology. The purpose of ISO/IEC TR 27023 is to show the corresp…