LOGBOOK

HELP

1 / 29
Other keys: showSpace: good1-4: rate0: skip5: flag

Question

What is an Information Security Management System (ISMS) and what is its purpose?

Answer

An ISMS is a set of rules and procedures that an organization uses to define, manage, control, maintain, and continuously improve information security.

An ISMS serves two main purposes:

  1. Protect assets — Ensure that the organization's assets and information are adequately protected
  2. Meet requirements — Fulfill legal, regulatory, industry, and market requirements

How it works in practice:

  • Maintain a process for identifying and assessing information security risks
  • Determine and implement controls
  • Continuously improve over time
  • Determine the protection needs of assets, define protective measures, and establish monitoring

Various standards (ISO 27001, BSI) provide frameworks for building an ISMS. Think of the ISMS not as a product you buy, but as an ongoing process that your organization runs.

Go deeper:

or press any other key

Question

What are the six core standards in the ISO 27000 family and what does each one cover?

Answer

The ISO 27000 family includes 27000 (vocabulary), 27001 (requirements), 27002 (controls), 27003 (implementation), 27004 (measurement), and 27005 (risk management).

ISO 27000 family hub: 27000 vocabulary, 27001 requirements, 27002 controls, 27003 implementation, 27004 measurement, 27005 risk.

* The six core ISO 27000 standards — only 27001 (requirements) is certifiable. *

There are over 50 standards in the family, but these six are the most important:

Standard Title Purpose
ISO 27000 Overview and vocabulary Defines terms used across the standard family
ISO 27001 ISMS Requirements Defines mandatory requirements for an ISMS (certifiable!)
ISO 27002 Code of Practice Provides 114 security controls with implementation guidance
ISO 27003 Implementation Guidance Recommendations for implementing an ISMS
ISO 27004 Measurement How to measure ISMS effectiveness
ISO 27005 Risk Management Framework for information security risk management

Key distinction: ISO 27001 is normative (uses "shall" — hard requirements, certifiable), while 27002-27005 are informative (uses "should" — guidelines and recommendations, not certifiable on their own).

Go deeper:

or press any other key