IASAbout IASDesignHostingPromotionConsultingContact


    Standards Policy Security













Standards Policy Security


ISO/IEC 27002:2005 - Information technology -- Code of practice for information security management ISO/IEC 27002 (previously known as ISO/IEC 17799 and before that BS 7799 Part 1) is an international standard providing best practice advice on information security management systems.

    Top: Computers: Security: Policy: Standards
See Also:

  • Praxiom Research Group Ltd. - Plain English descriptions of ISO/IEC 27001, 27002 and other standards, including a list of the controls.
  • ISO/IEC 27002 Explained - Information on ISO/IEC 27001 and 27002 from BERR, the UK government department for Business Enterprise and Regulatory Reform (formerly the DTI, the Department of Trade and Industry).
  • BITS Financial Services Roundtable - Security assessment questionnaire and review process based on ISO/IEC 27002 (access requires free registration). Also information on the overlaps between ISO/IEC 27002, PCI-DSS 1.1 and COBIT.
  • ISO 27001 Security - Information about the ISO/IEC 27000-series information security standards and other related standards, with discussion forum and FAQ.
  • The Security Practitioner - The ISO 27001 Perspective: An Introduction to Information Security is a guide to ISO/IEC 27001 and 27002 in the form of an HTML help file.
  • ISO 27000 Toolkit - Package containing the ISO/IEC 27001 and 27002 standards plus supporting materials such as policies and a glossary.
  • Yahoo! Groups ISO17799security - Mailing list to share knowledge about Information Security Management Systems based on the ISO/IEC 27000-series standards.
  • Yahoo! Groups iso-27001 - Discussion forum for ISO/IEC 27001 and 27002
  • NERC Reliability Standards - Information on the development of cyber and information security standards with emphasis on reliability.
  • Orange Parachute - An information security and integrated systems management consultancy specializing in ISO/IEC 27001 certification, audits, assessments and training.
  • NIST Special Publication 800-53 - Recommended Security Controls for Federal Information Systems has a similar scope to ISO/IEC 27002 and cross-references the standard. [PDF]
  • Overview of Information Security Standards - Report by the Government of the Hong Kong Special Administrative Region outlines the ISO/IEC 27000-series standards plus related standards, regulations etc. including PCI-DSS, COBIT, ITIL/ISO 20000, FISMA, SOX and HIPAA. [PDF]
  • Common Criteria - Provides the Common Criteria for Information Technology Security Evaluation, also published as ISO/IEC 15408.
  • The ISO 27000 Directory - Information covering the ISO/IEC 27000 series of standards, including updates and consultants directory
  • The SoGP - Information on the Standard of Good Practice for Information Security, which is published by the ISF and addresses information security from a business perspective.
  • ISO27k Implementers' Forum - Google Groups forum for those actively implementing the ISO/IEC 27000-series standards. Membership required for viewing content.
  • Wikipedia: ISO/IEC 27000-series - Open encyclopedia entry for the ISO/IEC 27000 family of information security management system standards.
  • ISO/IEC 27001 Frequently Asked Questions - FAQ covers the basics of ISO/IEC 27001, the ISO/IEC standard Specification for an Information Security Management System.
  • Information Governance Limited - Supplier of Proteus Enterprise security risk management software for compliance with ISO/IEC 17799 and related information security, risk management and IT governance standards.
  • IT Governance Limited - Information, books, tools and training for developing and implementing an information security management system in line with the international best-practice specification ISO/IEC 27001.
  • ISO 27001 Certificates - List of organizations certified against ISO/IEC 27001 or equivalent national standards, maintained by the ISMS International User Group based on inputs from all the certification bodies.
  • Veridion - ISO/IEC 27001 and 27002 training courses including Lead Auditor and Lead Implementer, plus other information security, risk management and business continuity courses on BS 25999, CISSP, CISA, CISM, MEHARI and OCTAVE.
  • ISO/IEC 27002:2005 Information Technology - Code of Practice for Information Security Management - ISO site outlines the contents of the standard.


Help build the largest human-edited directory on the web.
Submit a Site - Open Directory Project - Become an Editor
Click here to add, change or remove your listing

Top


Home | About IAS | Web Design | Web Hosting | Promotion | Consulting | Support | Contact IAS

Copyright © 1995-2009 Internet Advertising Solutions, Inc.
Copyright Notice | Privacy Policy | Site Map | APR









  MySQL - Cache Direct sec.