Information is key to the growth and success of an organization. ISO 27001 is an information security management system (ISMS) standard published in October 2005 by the International Organization for Standardization and International Electrotechnical Commission.
The ISO 27001 standard was published in 2005, and revised in September 2013, essentially replacing the old BS7799-2 standard. The Revised ISO 27001-2013 is putting more emphasis on measuring and evaluating ISMS performance as well as more controls for new section on outsourcing considering the nature of IT business. BS7799 itself was a long standing standard, first published in the nineties as a code of practice. As this matured, a second part emerged to cover management systems. It is this against which certification is granted. Today in excess of a thousand certificates are in place, across the world.
ISO 27001:2013 enhanced the content of BS7799-2 and harmonized it with other standards. A scheme has been introduced by various certification bodies for conversion from BS7799 system to ISO 27001 system.
By implementing information security management system as per ISO 27001:2013 standard, organization can achieve following benefits from the iso 27001 systems with continuous improvements.