Welcome to i will share a standard called ISO/IEC 27000:2018,whose title is Information technology — Security techniques — Information security management systems — Overview and vocabulary.
International Standards for management systems provide a model to follow in setting up and operating a management system. This model incorporates the features on which experts in the field have reached a consensus as being the international state of the art. ISO/IEC JTC 1/SC 27 maintains an expert committee dedicated to the development of international management systems standards for information security, otherwise known as the Information Security Management system (ISMS) familyof standards.
Through the use of the ISMS family of standards, organizations can develop and implement a framework for managing the security of their information assets, including financial information, intellectual property, and employee details, or information entrusted to them by customers or third parties. Theses standards can also be used to prepare for an independent assessment of their ISMS applied to theprotection of information.
Purpose of this document
The ISMS family of standards includes standards that:
a) define requirements for an ISMS and for those certifying such systems
provide direct support, detailed guidance and /or interpretation for the overall process to establish,
implement,maintain, and improve an ISMS;
c) address sector-specific guidelines for ISMS; and
d) address conformity assessment for ISMS.
