New ISO/IEC standard gives overview of information security management systems
ISO/IEC 27005:2008
Information technology -- Security techniques -- Information security risk management
This standard has been revised by: ISO/IEC 27005:2011
Abstract
ISO/IEC 27005:2008 provides guidelines for information security risk management. It supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach. Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 and ISO/IEC 27002 is important for a complete understanding of ISO/IEC 27005:2008. ISO/IEC 27005:2008 is applicable to all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations) which intend to manage risks that could compromise the organization's information security.
-
Edition: 1 (Monolingual) ICS: 35.040 Status: Withdrawn Stage: 95.99 (2011-05-19) TC/SC: ISO/IEC JTC 1/SC 27 Number of Pages: -
Revised by: ISO/IEC 27005:2011
Revises: ISO/IEC TR 13335-3:1998
Revises: ISO/IEC TR 13335-4:2000


