SafeTok helps with ISO 27001 compliance ISO 27001 (its formal name is ISO/IEC 27001:2005) is a global specification for an information security management system (ISMS).
An ISMS is a set of writen policies and documented procedures which include all legal, physical and technical controls that are involved in an organisation's information risk management processes.
ISO 27001 was developed to provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an information security management system. It uses a topdown, technology neutral, risk-based.
The specification defines a six-part planning process:
The 27001 specification includes details for documentation, management responsibility, internal audits, continual improvement, and corrective and preventive action. The standard requires close and continued cooperation among all sections of an organisation.
The 27001 standard does not mandate specific information security controls, but it provides a checklist of controls that should be considered in the accompanying code of practice, ISO/IEC 27002:2005.
This second standard describes a comprehensive set of information security control objectives and a set of generally accepted good practice security controls.
ISO 27002 contains 12 main sections:
Third-party accredited certification is recommended for ISO 27001 conformance.
Other standards being developed in the 27000 family are: 27003 – implementation guidance.