Information technology includes hardware and software. Unless these two parts are not
secured, information cannot be protected. To provide security on hardware and software, two
different standards namely International Organization of Standardization (IS0) and
International Electrotechnical Commission (IEC) are developed. These two standards when
combine becomes a strong family of standards which is known as ISO/IEC 27000 suite of
security standards. This standard is also known as ISO 27000 series (Stallings, 1). The most
serious risk organizations are facing every day is data breaches. As new technologies have
been developing, cyber criminals are also growing simultaneously. If hackers use sensitive
data for illegitimate purposes, organizations must lose huge amount of assets as well as
company’s reputation that can be devastating for them.++Before that event happens,
organizations decide to invest lots of money on ISO 27000 series. The purpose of this series
is how to set up best practices for information security (Irwin, 2).
+
ISO/IEC family has long list of individual standards that has their own role in securing
data.++Some core standards are listed below (Irwin, 2).
+
ISO 27001 - The only standard that audits and certifies organization.
+
ISO 27002 – This standard provides security control of organization to be implemented.
+
ISO 27005- This standard provides guidelines for information security risk management
system.
+
ISO 27017- This standard controls data in the cloud (Irwin, 2).
+
These days, owners of companies are aware of data breaches. As soon as they could, they
give more priority investing on implementing guidelines such as ISO 27000 series. This
series can bring more value in cybersecurity because of its capability of dealing problems
associated with Information Security Management System (ISMS). Besides, for every size of
businesses, ISO 27000 series provides security of information assets.++The chance of data lost
is least since there are standard series that provides guidelines how to save sensitive data in
cloud. Creating security environment brings good reputation in industries and can build more
trust on customers (Stalling, 1).
+
Sources
William Stallings. 2019.Effective Cybersecurity: A Guide to Using Best
Practices and Standards.CIS512 Pearson Education 1st edition textbook
Luke Irwin.2020.What is the ISO 27000 series of standards? - IT Governance.https://www.itgovernance.co.uk >
blog > what-is-the-iso....