Information technology. Security techniques. Code of practice for information security management
BS ISO/IEC 17799:2005This universal standard provides a complete set of guidelines for an effective Information Security Management System (ISMS). It is essential guidance to help you manage an effective information security policy. It offers a common language and a common understanding to enable your organization to develop, implement and measure effective security management practice, providing confidence in inter-company trading.
More user-friendly and accessible, this newly revised edition:
- takes into account changes in technology, technical upgrades and compatibility issues
- takes on board current security techniques
- provides additional controls focusing on management controls including asset management, incident management and service delivery management
- enhances and revises existing control
- puts best practice into an international context
Contents
Foreword
Introduction
- Scope
- Terms and Definitions
- Structure of this Standard
- Risk Assesment and treatment
- Security policy
- Organization of Information Security
- Asset Management
- Human Resources Security
- Physical and Environmental Security
- Communications and Operation Management
- Access Control
- Information Systems Acquisitions , Development and Maintenance
- Information Security, Incident Management
- Business Continuity Management
-
Compliance
Bibliography
Index


