Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  



























Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1Overview and introduction
 




2Glossary
 




3See also
 




4References
 













ISO/IEC 27000






Español
فارسی
Français

עברית
Nederlands
Português
Русский
Slovenščina
Suomi
Svenska
Tiếng Vit
Yorùbá
 

Edit links
 









Article
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Cite this page
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 


















From Wikipedia, the free encyclopedia
 


ISO/IEC 27000 is one of the ISO/IEC technical standards in the ISO/IEC 27000 seriesofInformation Security Management Systems (ISMS)-related standards. The formal title for ISO/IEC 27000 is Information technology — Security techniques — Information security management systems — Overview and vocabulary.

The standard was developed by subcommittee 27 (SC27) of the first Joint Technical Committee (JTC1) of the ISO and IEC.[1]

ISO/IEC 27000 provides:

ISO/IEC 27000 is available for free via the ITTF website.[2]

Overview and introduction[edit]

The standard describes the purpose of an Information Security Management System (ISMS), a management system similar in concept to those recommended by other ISO standards such as ISO 9000 and ISO 14000, used to manage information security risks and controls within an organization. Bringing information security deliberately under overt management control is a central principle throughout the ISO/IEC 27000 standards.

Glossary[edit]

Information security, like many technical subjects, is evolving a complex web of terminology. Relatively few authors take the trouble to define precisely what they mean, an approach which is unacceptable in the standards arena as it potentially leads to confusion and devalues formal assessment and certification. As with ISO 9000 and ISO 14000, the base '000' standard is intended to address this.

The target audience is users of the remaining ISO/IEC 27000-series information security management standards.

See also[edit]

References[edit]

  1. ^ ISO/IEC 27000:2016
  • ^ "Publicly Available Standa=2014-11-05".

  • t
  • e

  • Retrieved from "https://en.wikipedia.org/w/index.php?title=ISO/IEC_27000&oldid=1161538574"

    Categories: 
    ISO/IEC standards
    Standards and measurement stubs
    Hidden categories: 
    Articles with short description
    Short description is different from Wikidata
    Articles lacking reliable references from April 2017
    All articles lacking reliable references
    Use Oxford spelling from January 2012
    All stub articles
     



    This page was last edited on 23 June 2023, at 11:05 (UTC).

    Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



    Privacy policy

    About Wikipedia

    Disclaimers

    Contact Wikipedia

    Code of Conduct

    Developers

    Statistics

    Cookie statement

    Mobile view



    Wikimedia Foundation
    Powered by MediaWiki