ISO IEC 27002 2005 TRANSLATED INTO PLAIN ENGLISH: I SO IEC 27002 2005 is now OBSOLETE. Please see ISO IEC 27002 2013. 5. Security Policy Management : 5.1 Establish an information security policy: 5.1.1 Develop an information security policy document. 5.1.2 1. what an effective ISMS according ISO/IEC 27001 is and what mandatory elements it consists of. 2. what the main differences are between the “twin standards” ISO/IEC 27001 and ISO/IEC 17799 3. how to improve the existing security processes to a certifiable ISMS 4. why this makes sense even if your company doesn’t Standard used is framework international standardization organization (ISO) 17799:2005. Management audit is very important for assessment of their information technology management to gain efficient and effective business running process. Phần I của chuẩn BS 7799 là một hướng dẫn thi hành dựa trên đề nghị các kiểm soát ATTT và là cơ sở hình thành tiêu chuẩn quốc tế ISO 17799:2000. Từ năm 2005, tiêu chuẩn ISO 17799:2000 được tổ chức ISO/IEC thay thế chính thức bằng tiêu chuẩn quốc tế ISO/IEC 17799:2005 và ГОСТ Р ИСО/МЭК 17799-2005. ГОСТ в актуальной редакции. Информационная технология. ISO/IEC 17799 — стандарт информационной безопасности, опубликованный в 2005 году организациями ISO и IEC. Он озаглавлен Информационные технологии — Технологии

Muere la ISO 17799 y Nace la ISO 27002 El pasado 01 de julio, ISO publicó lo que llaman un “ Technical Corrigendum ” (en concreto el “ISO/IEC 17799:2005/Cor.1:2007-07-01 - Information technology ― Security techniques ― Code of practice for information security management”). This Management Guide provides an overview of the implementation of an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2005 and which uses controls derived from ISO/IEC 17799:2005. Technical Corrigendum 1 to ISO/IEC 17799:2005 was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee SC 27, IT Security techniques. Throughout the document: Replace “17799” with “27002”. Please see the administrative notes on page iii Apoya los conceptos generales especificados en la norma ISO/IEC 27001:2005 y está diseñada para ayudar a la aplicación satisfactoria de la seguridad de la información basada en un enfoque de gestión de riesgos. Su primera publicación revisó y retiró las normas ISO/IEC TR 13335-3:1998 e ISO/IEC …

