With increasing information technologies in organisations difficult information systems are established. There is tendency of organisations to safe important information, information of partnership organisations and customers information.
Information Security Management System (ISMS) provides overall model modifying risk assessment, plan and information security establishment, information security management and information security reassessment.
Proposal and implementation of ISMS in an organisation is conditioned by needs and objectives of organisation activities and resulting requirements for security, used processes, size and structure of an organisation. ISMS ensures appropriate security inspections, adequate information resources security and it provides appropriate safety to customers and to other interested parties.
ISO/IEC 27001 Information Security Management Systems (ISMS) – Specification guideline for implementation – is the standard which specifies the requirements for implementation, establishment, operation, monitoring, research, maintenance and improvement of documented ISMS. It specifies requirements for establishment of safety inspections, adapted according to needs of an organisation.
The organisation declares the assurance of information security management system requirements by certification according to ISO/IEC 27001. A certified organisation is qualified to use a certification mark for certified scopes.
EXAMPLE: Certificate ISO/IEC 27001
Certification mark ISO/IEC 27001