ISO/IEC 27005 will assist organizations in their information security risk management

Organizations of all types are very concerned by threats that could compromise their information security and managing this aspect has become a primary concern for their information technology (IT) departments.

The new International Standard ISO/IEC 27005:2008, which describes the information security risk management process and associated actions, will help them to manage risks.
Threats may be deliberate or accidental, and may relate to either the use and application of IT systems or to IT's physical and environmental aspects. These threats may take any form from identity theft, risks of doing business on-line, denial of service attacks, remote spying, theft of equipment or documents through to a seismic or climatic phenomenon, fire, floods or pandemic problems. These threats may result in various business impacts, for example, financial loss or damage, loss of essential network services, loss of customer confidence through to loss power supply or failure of telecommunication equipment.
A risk is a combination of the consequences that would follow from the occurrence of an unwanted event and the likelihood of the occurrence of the event. Risk assessment quantifies or qualitatively describes the risk and enables managers to prioritize risks according to their perceived seriousness or other established criteria.
ISO/IEC 27005:2008, Information technology – Security techniques – Information security risk management, provides guidelines for information security risk management and supports the general concepts specified in ISO/IEC 27001:2005, Information technology – Security techniques – Information security management systems – Requirements.
The new standard is designed to assist the implementation of ISO/IEC 27001, the information security management system standard, which is based on a risk management approach. Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 and ISO/IEC 27002: 2005, Information technology – Security techniques – Code of practice for information security management, is important for a complete understanding of this International Standard.
The information security risk management process consists of:
  - context establishment 
  - risk assessment 
  - risk treatment 
  - risk acceptance 
  - risk communication, and 
  - risk monitoring and review.
However, ISO/IEC 27005:2008 does not provide any specific methodology for information security risk management. It is up to the organization to define its approach to risk management, depending, for example, on the scope of the information security management system, based on the context of risk management, or the industry sector.
Edward Humphreys, convener of the ISO/IEC working group that developed the standard comments: “Today, most organizations recognize the critical role that information technology plays in supporting their business objectives and with the advent of the Internet and the prospect of performing business online, IT security has been in the forefront. ISO/IEC 27005:2008 is relevant to managers and staff concerned with information security risk management within an organization and, where appropriate, external parties supporting such activities.”

Resource: http://www.iso.org

 
 
Add To Facebook     Add To Twitter              Print | Send | 18 Eylül 2009 Cuma
Last 10 News
23.09.2011 | Are you ready? New ISO standard for ensuring resilience throughout the supply chain
23.09.2011 | ISO publishes Six Sigma performance-improvement methodology
23.09.2011 | Is your biometric data safe online? ISO/IEC standard ensures security and privacy
05.07.2010 | Measuring customer satisfaction with new ISO technical specification
05.07.2010 | ISO standards expected to improve quality of marine fuels
09.11.2009 | Launching of The ISO Concept Database (ISO/CDB) will benefit standards users and developers
09.11.2009 | ISO, ILAC and IAF streamline quality management requirements for medical laboratories
09.11.2009 | ISO standard to increase confidence in ship recycling certification
09.11.2009 | ISO standard for cruise control systems promises safer and more enjoyable driving
09.11.2009 | WARC – new ISO file format to store billions of online data
Click Here All News

We are looking forward
to working with you.
Phone: +90 0212 211 16 16
Fax: +90 0212 356 20 02
kalite@acarkalite.com
Quality and productivity improvement through our trainings

Quality management system training serves to provide a framework that enables a company to use industry standard vocabulary when describing quality management procedures and processes. Employees who do not deal with customers directly often lack the motivation to improve processes without understanding the direct impact their work has on customer satisfaction and company profit. Click here to see our training programs.
OUR CLIENTS More >>
         
 
Copyright © 2004 | ACAR Quality Consulting Ltd  
ISO 9001       ISO 14001       ISO 22000       HACCP       ISO 18001       ISO13485