THEORETICAL AND PRACTICAL CONSIDERATIONS REGARDING THE INFORMATION SECURITY MANAGEMENT SYSTEM WITHIN ORGANIZATIONS IN CONCORDANCE WITH THE NEW INTERNATIONAL STANDARD ISO/IEC 27001:2013

被引:0
|
作者
Tiganoaia, Bogdan [1 ]
机构
[1] Univ Politehn Bucuresti, Bucharest, Romania
关键词
information security; standards; management systems; organizations; ISO;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
This paper presents theoretical aspects regarding the information security management system in an organization, such as (selection): what is an ISMS - Information Security Management System, the importance of the implementation and certification of an information security management system in an organization, a statistics regarding the global growth in certification etc. The focus point of the paper is on the structure of the new standard ISO/IEC 27001: 2013. The paper also presents some practical aspects for organizations and offers answers to some Frequently Asked Questions - FAQ regarding new concepts, requirements and changes introduced in the standard, what should do an organization if it is currently certified or is interested in certifying ISO/IEC 27001 now etc.
引用
收藏
页码:62 / 68
页数:7
相关论文
共 15 条