ISO/IEC 27010 was first published in 2012 then minor
editorial changes were made to align the standard with the 2013 editions of
ISO/IEC 27001 and 27002.The 2nd edition was published in December 2015. This
standard provides guidance in relation to sharing information about information
risks, security controls, issues and/or incidents that span the boundaries
between industry sectors and/or nations, particularly those affecting “critical
infrastructureâ€. ISO/IEC 27010 provides guidance on information security
interworking and communications between industries in the same sectors, in
different industry sectors and with governments, either in times of crisis and
to protect critical infrastructure or for mutual recognition under normal
business circumstances to meet legal, regulatory and contractual obligations. Sometimes
it is necessary to share confidential information regarding information-related
threats, vulnerabilities and/or incidents between or within a community of
organizations, for example when private companies, governments, law enforcement
and CERT-type bodies are collaborating on the investigation, assessment and
resolution of serious pan-organizational and often international or pan-jurisdictional
cyber attacks. Such information is often highly sensitive and it may need, for
example, to be restricted to certain individuals within the recipient
organizations. Information sources may need to be protected by remaining
anonymous. Such information exchanges typically happen in a highly charged and
stressful atmosphere under intense time pressures - hardly the most conducive
environment for establishing trusted working relationships and agreeing on
suitable information security controls. The standard should help by laying out
common ground-rules for security. The standard provides guidance on methods,
models, processes, policies, controls, protocols and other mechanisms for the
sharing of information securely with trusted counterparties on the understanding
that important information security principles will be respected. ISO/IEC
27010:2012 provides guidelines in addition to guidance given in the ISO/IEC
27000 family of standards for implementing information security management
within information sharing communities.ISO/IEC 27010:2012 provides controls and
guidance specifically relating to initiating, implementing, maintaining, and
improving information security in inter-organizational and inter-sector
communications.ISO/IEC 27010:2012 is applicable to all forms of exchange and
sharing of sensitive information, both public and private, nationally and
internationally, within the same industry or market sector or between sectors.
In particular, it may be applicable to information exchanges and sharing
relating to the provision, maintenance and protection of an organization's or
nation states critical infrastructure. This International Standard provides
controls and guidance specifically relating to initiating, implementing, maintaining,
and improving information security in inter-organizational and inter-sector
communications. It provides guidelines and general principles on how the
specified requirements can be met using established messaging and other
technical methods. This International Standard is applicable to all forms of
exchange and sharing of sensitive information, both public and private,
nationally and internationally, within the same industry or market sector or
between sectors. In particular, it may be applicable to information exchanges
and sharing relating to the provision, maintenance and protection of an
organization's or nation states critical infrastructure. It is designed to
support the creation of trust when exchanging and sharing sensitive information,
thereby encouraging the international growth of information sharing
communities.
User questions & answers