ISO 27000 Series Flashcards
Which ISO contains guidelines for initiating, implementing, maintaining, and improving an ISMS within an organization. Organizational security standards and effective security management practices?
ISO 27002 (Code of Practice)
Which ISO provides an Information Security Management System (ISMS) overview and vocabulary. Structure of an ISMS, ISO/IEC 27000 series explained and terminology defined?
ISO 27000 (Overview and Vocabulary)
Which ISO explains the requirements for establishing, implementing, maintaining and continuously improving an ISMS. Requirements must be met for certification purposes?
ISO 27001 (Requirements)
Which ISO explains the requirements for entities that certify ISMSs. Accreditation standard that guides certification bodies on the formal process they must follow when auditing an ISMS?
ISO 27006 (Certification Body Requirements)
Which ISO provides guidelines for accredited certification bodies, internal auditors, external/third party auditors on how to audit an ISMS based upon the ISO 27001 requirements?
ISO 27007 (Audit Guidelines)
Which ISO provides guidelines for ISMS implementation? How to build an ISO 27001 compliant ISMS. Scoring and defining boundaries, assessing risks, risk treatments, control requirements and implementation planning?
ISO 27003 (Implementation Guidance)
Which ISO gives guidelines for security risk management? Identifying assets, threats, vulnerabilities, and impacts? Systems approach to risk analysis and developing a risk treatment plan?
ISO 27005 (Risk Management)
Which ISO gives guidelines for security measurement? Guidance on the development and use of metrics and measurements in order to assess the effectiveness of an implemented ISMS?
ISO 27004 (Measurements)
Which ISO provides guidelines on security management for telecommunications organizations? Development and managing an ISMS within the context of the telecommunication’s overall business risks?
ISO 27011 (Telecommunications Organizations)
Which ISO gives guidelines for health informatics? Best practice guidelines and a set of controls for managing health information security?
ISO 27799 (Health Organizations)