Consultant - Training - Workshop ISO 27000 Standard - Certification Jakarta
PERKEMBANGAN ISO 2700O
Sejak penerbitan pertama ISO/IEC 17799 pada Desember 2000,
ISO/IEC selalu sibuk dalam melakukan standarisasi information security
management practices and requirements. Selanjutnya, penerbitan
ISO/IEC 27001 tentang "Information Security Management System (ISMS)
requirements” dan revisi ISO/IEC 17799 pada tahun 2005 adalah merupakan tonggak
utama dalam perjalanan perkembangan standarisasi information security
management.
ISO/IEC 27000
Series juga dikenal sebagai "ISMS Family
of Standards” atau istilah pendeknya "ISO27K”.
Standard ISO 27000 Series secara spesifik telah ditetapkan oleh ISO untuk
urusan yang terkait dengan information security. ISO 27000 Series memberikan
rekomendasi tentang information security management, risks dan controls di
dalam konteks Information Security Management System (ISMS) secara keseluruhan,
dimana dari segi design ISO 27000 Series mirip dengan management systems for
quality assurance (ISO 9000 Series) dan environmental protection (ISO 14000
Series).
Untuk melihat
perkembangan keluarga ISO 27000 lebih lanjut, silakan simak Rangkuman
tentang ISO 27000 Series.
ISO 27000:
Information security management systems — Overview and vocabulary, contains
definitions of information security used as basic terminology in the ISO 27000
series.
ISO 27001:
Information security management systems — Requirements, contains supporting
aspects in implementing ISMS of an organization.
ISO 27002: Code
of practice for information security management, related to ISO 27001 document,
this document contains practical guide for implementing ISMS of an
organization.
ISO 27003:
Information security management system implementation guidance.
ISO 27004:
Information security management — Measurement.
ISO 27005:
Information security risk management.
ISO 27006:
Requirements for bodies providing audit and certification of information
security management systems.
ISO 27007:
Guidelines for information security management systems auditing (focused on the
management system)
ISO 27008:
Guidance for auditors on ISMS controls (focused on the information security
controls) – In preparation.
ISO 27010:
Information technology — Security techniques — Information security management
for intersector and inter-organisational communications – In preparation.
ISO 27011:
Information security management guidelines for telecommunications organizations
based on ISO 27002.
ISO 27013:
Information technology — Security techniques — Guidelines on the integrated
implementation of ISO/IEC 27001 and ISO/IEC 20000-1.
ISO 27014:
Information security governance framework.
ISO 27015:
Information security management guidelines for the finance and insurance sectors.
ISO 27016:
Information technology — Security techniques — Information security management
— Organizational economics.
ISO 27017: The
suggestion was that ISO 27010 through ISO 2
...
Read more »