Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

ISO/IEC 27000

From Wikipedia, the free encyclopedia
This article is about the individual 27000 standard. For the family of standards, seeISO/IEC 27000 family.
Information security management system standard
icon
This articlerelies excessively onreferences toprimary sources. Please improve this article by addingsecondary or tertiary sources.
Find sources: "ISO/IEC 27000" – news ·newspapers ·books ·scholar ·JSTOR
(April 2017) (Learn how and when to remove this message)

ISO/IEC 27000 is one of thestandards in theISO/IEC 27000 series ofinformation security management systems (ISMS)-related standards. The formal title for ISO/IEC 27000 isInformation technology — Security techniques — Information security management systems — Overview and vocabulary.

The standard was developed bysubcommittee 27 (SC27) of the first Joint Technical Committee (JTC1) of theInternational Organization for Standardization (ISO) andInternational Electrotechnical Commission (IEC).[1]

ISO/IEC 27000 provides:

  • An overview of, and introduction to, the entire ISO/IEC 27000 series.
  • A formally defined glossary or vocabulary of the specialist terms used throughout the ISO/IEC 27000 series.

ISO/IEC 27000 is available for free via theITTF website.[2]

Overview and introduction

[edit]

The standard describes the purpose of an ISMS, amanagement system similar in concept to those recommended by otherISO standards such asISO 9000 andISO 14000, used to manage information securityrisks andcontrols within anorganization. Bringinginformation security deliberately under overt management control is a central principle throughout the ISO/IEC 27000 series of standards.

The target audience is users of the remaining ISO/IEC 27000-series information security management standards.

Glossary

[edit]

Information security, like many technical subjects, is evolving a complex web of terminology. Relatively few authors take the trouble to define precisely what they mean, an approach which is unacceptable in the standards arena as it potentially leads to confusion and devalues formal assessment and certification. As withISO 9000 andISO 14000, the base '000' standard is intended to address this.

See also

[edit]

References

[edit]
  1. ^ISO/IEC 27000:2018
  2. ^"Publicly Available Standards". ISO. Retrieved22 July 2024.
1–9999
10000–19999
20000–29999
30000+
IEC
ISO/IEC
Related
Stub icon

Thiscomputer security article is astub. You can help Wikipedia byadding missing information.

Stub icon

Thisstandards- ormeasurement-related article is astub. You can help Wikipedia byadding missing information.

Retrieved from "https://en.wikipedia.org/w/index.php?title=ISO/IEC_27000&oldid=1304952608"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp