ISO 27002
The ISO 27002 standard is a collection of information security management guidelines that are intended to help an organization implement, maintain, and improve its information security management system. The standard is published by the ISO and the International Electrotechnical Commission (IEC). ISO 27002 is designed to work with ISO 27001, which provides the requirements for establishing, implementing, maintaining, and improving an ISMS. ISO 27002 provides guidelines, general principles, and control mechanisms for implementing, maintaining, and improving information security management in an organization.
Benefits
- Better awareness of information security.
- Greater control of sensitive assets and information.
- Provides an approach for implementation of control policies.
- Opportunity to identify and correct weaknesses.