The ISO/IEC 27002 standard is part of a family of international standards (ISO 27000) for the management of information security. It includes the best industry practices to protect the availability, integrity and confidentiality of information. A risk assessment is initially necessary to identify priority controls to be implemented within a company in order to improve the information’s security level.
The ISO/IEC 27002 is an international standard used as a reference for selecting and implementing information security controls. In addition, it guides on the information security best practices that help organizations in selecting, implementing, and managing information security controls such as organizational, people, physical, and technological controls, among others.
ISO/IEC 27002:2013 gives guidelines for organizational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organization’s information security risk environment(s).
ISO/IEC 27002 applies to all types and sizes of organizations, including public and private sectors, commercial and non-profit that collect, process, store and transmit information in many forms including electronic, physical and verbal.
Key clauses of ISO/IEC 27002:2013
ISO/IEC 27002 is organized into the following main clauses:
The standard contains 14 security control clauses, collectively containing a total of 35 main security categories and 114 controls.
Clause 5: Information Security Policies
Clause 6: Organization of Information Security
Clause 7: Human Resource Security
Clause 8: Asset Management
Clause 9: Access Control
Clause 10: Cryptography
Clause 11: Physical and Environmental Security
Clause 12: Operations Security
Clause 13: Communication Security
Clause 14: System Acquisition, Development and Maintenance
Clause 15: Supplier Relationships
Clause 16: Information Security Incident Management
Clause 17: Information Security Aspects of Business Continuity Management
Benefits of ISO/IEC 27002
By implementing information security controls found in ISO 27002, organisations can rest assured that their information assets are protected by internationally recognized and approved standards. Organisations of all sizes and levels of security maturity can reap the following benefits from adherence to the ISO 27002 code of practice:
- It provides a working framework for the resolution of information security issues.
- Clients and business partners will be more confident and have a positive perception of an organisation that implements the recommended standards and controls.
- Since the policies and procedures provided are in line with internationally recognized requirements, cooperation with foreign partners is made easier.
- Compliance with the ISO 27002 standard helps in the development of an organisation’s best practices which will increase the overall productivity.
- It provides a defined implementation, management, maintenance and evaluation of information security management systems.
- An ISO-compliant organisation will have an advantage in contract negotiations and participation in global business opportunities.
