ISO/IEC 27005
Information technology - Security techniques - Information security risk management
| Organization: | ISO |
| Publication Date: | 1 June 2011 |
| Status: | inactive |
| Page Count: | 76 |
| ICS Code (Information coding): | 35.040 |
scope:
This International Standard provides guidelines for information security risk management.
This International Standard supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach.
Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 and ISO/IEC 27002 is important for a complete understanding of this International Standard.
This International Standard is applicable to all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations) which intend to manage risks that could compromise the organization's information security.
Document History