ISO/IEC 27000
ISO/IEC 27000 is one of the standards in the ISO/IEC 27000 series of information security management systems -related standards. The formal title for ISO/IEC 27000 is Information technology — Security techniques — Information security management systems — Overview and vocabulary.
The standard was developed by subcommittee 27 (SC27) of the first Joint Technical Committee of the International Organization for Standardization and International Electrotechnical Commission.
ISO/IEC 27000 provides:
- An overview of, and introduction to, the entire ISO/IEC 27000 series.
- A formally defined glossary or vocabulary of the specialist terms used throughout the ISO/IEC 27000 series.
Overview and introduction
The standard describes the purpose of an ISMS, a management system similar in concept to those recommended by other ISO standards such as ISO 9000 and ISO 14000, used to manage information security risks and controls within an organization. Bringing information security deliberately under overt management control is a central principle throughout the ISO/IEC 27000 series of standards.The target audience is users of the remaining ISO/IEC 27000-series information security management standards.