23. ISO 27001 & 27002 Flashcards
1
Q
ISO 27001 & 27002
ISMS
A
Information Security Management System
- Lack of an ISMS system means controls are often disorganised and only gover part or some of the organisation
- Controls wil not be reactive
- Often seen in reactive organisations - something breaks, fix it, put controls on that system
2
Q
ISO 27001 & 27002
ISO/IEC 27001
A
Management System
Gives specific requirements
- A framework and can be assessed against to be certified
- Remember 1 = more important = Management of system
3
Q
ISO 27001 & 27002
ISO/IEC 27002
A
Best Practices
- the “How do we do it”. What are the practical steps we need to implement
- Remember 2 = Not as important as 1 = Best practice, less strict that management