US ISO/IEC 27001:2005

Information technology - Security techniques - Information security management systems - Requirements


Abstract

This Uganda Standard covers all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations). This standard specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented ISMS within the context of the organization`s overall business risks. It specifies requirements for the implementation of security controls customized to the needs of individual organizations or parts thereof. The ISMS is designed to ensure the selection of adequate and proportionate security controls that protect information assets and give confidence to interested parties.

This Standard was withdrawn and replaced by :

  US ISO/IEC 27001:2013