Information technology. Guidance on information security management system processes
Last updated: 18 Jul 2024
Development Stage
Pre-draft
Draft
Published
Scope
This document defines a process reference model (PRM) for the domain of information security management, which is meeting the criteria defined in ISO/IEC 33004 for process reference models (see Annex A). It is intended to guide users of ISO/IEC 27001 to:
ā incorporate the process approach as described by ISO/IEC 27000:2018, 4.3, within the ISMS;
ā be aligned to all the work done within other standards of the ISO/IEC 27000 family from the perspective of the operation of ISMS processes
ā support users in the operation of an ISMS ? this document is complementing the requirements-oriented perspective of ISO/IEC 27003 with an operational, process-oriented point of view. Ā© ISO/IEC 2022 All rights reserved
External Links
Let the community know
Categorisation
Key Information
Referenced standards: ISO/IEC 27000, ISO/IEC 27003:2017, ISO/IEC 27001:2013, ISO/IEC 33003:2015, ISO/IEC TR 24774:2010, ISO/IEC 27035-1:2016, ISO/IEC 27000:2018, ISO/IEC 33004:2015, ISO/IEC 38500:2015, ISO 9000:2015