23. ISO 27001 & 27002 Flashcards

1
Q

ISO 27001 & 27002

ISMS

A

Information Security Management System

  • Lack of an ISMS system means controls are often disorganised and only gover part or some of the organisation
  • Controls wil not be reactive
  • Often seen in reactive organisations - something breaks, fix it, put controls on that system
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO 27001 & 27002

ISO/IEC 27001

A

Management System
Gives specific requirements

  • A framework and can be assessed against to be certified
  • Remember 1 = more important = Management of system
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISO 27001 & 27002

ISO/IEC 27002

A

Best Practices

  • the “How do we do it”. What are the practical steps we need to implement
  • Remember 2 = Not as important as 1 = Best practice, less strict that management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly