ISO/IEC 27001 to protect business-critical data

An IEC (International Electrotechnical Commission) product story
Edited by the Engineeringtalk editorial team Nov 11, 2005

Things have just become tougher for hackers, as a new tool is now on the market to help companies protect information that is vital for doing business.

Things have just become tougher for hackers, as a new tool is now on the market to help companies protect information that is vital for doing business.

A new international standard, jointly published by the International Electrotechnical Commission (IEC) and ISO, the International Organization for Standardization, integrates a process-based approach to management system standards designed to enhance security and protect information.

ISO/IEC 27001 'Information technology - Security techniques - Information security management systems - Requirements', combats information security flaws and prevents threats to ensure business continuity, minimise business damage and maximise return on investments and business opportunities.

"The publication of ISO/IEC 27001 is a big event in the world of information security and the standard has been eagerly awaited," says Ted Humphreys, convenor of the working group responsible for managing the development of the standard.

"It is a standard that all security-conscious organisations should look to implement".

Intended for businesses of all sizes and across a broad range of commercial and industry sectors, the standard specifies a general framework for establishing, reviewing and monitoring, managing and maintaining an effective information security management system (ISMS).

The standard's developers say that it will reassure customers and suppliers that information security is taken seriously within the organisations they work with because they have in place state-of-the-art processes to deal with information security threats and issues.

The new standard forms a complementary pair with the recently revised ISO/IEC 17799: 'Information technology - Security techniques - Code of practice for information security management', which describes individual security controls that may be applied as part of the security management system described by ISO/IEC 27001.

The new version of ISO/IEC 17799 addresses the security of information in its widest sense, providing best business practice, guidelines and general principles for implementing, maintaining and managing information security in any organisation that produces and uses information in any form.

Organisations voluntarily seeking independent certification of their information security management systems can use ISO/IEC 27001.

* About the IEC.

The International Electrotechnical Commission (IEC) is the global organisation responsible for developing and publishing international standards and specifications for all electrical, electronic and related technologies.

The membership consists of more than 60 participating countries, including all the world's major trading nations and a growing number of industrialising countries.

Its standards are used in more than 100 countries as the basis for national rules and standards.

Not what you're looking for? Search the site.

Back to top Back to top

Google Ads

 

Contact IEC (International Electrotechnical Commission)

Related Stories

Contact IEC (International Electrotechnical Commission)
Newsletter sign up

Request your free weekly copy of the Engineeringtalk email newsletter ...

Articles by product category

All suppliers A - Z

A Pro-talk Publication

A Pro-talk publication