The six parts to the 27000 series each deal with a different area of an Information Security Management System (ISMS). This document will briefly outline each section and then concentrate on ISO 27001, the section that details the requirements for ISMS. An overview of what the series deals with can be found in the table below.
ISO
27000 Series-
ISO27001 ISMS Requirements
ISO27002 ISMS controls
ISO27003 ISMS implementation guidelines
ISO27004 ISMS Measurements
ISO27005 Risk management
ISO27006 Guidelines for ISO 27000 accreditation bodies
As
can be seen in the table above, ISO 27001 details the actual requirements for
businesses to comply with the ISO 27000 standard. ISO 27002 builds on ISO 27001 by providing a
description of the various controls that can be utilized to meet the
requirements of ISO 27001. ISO 27003
provides details on the implementation of the standard including project
approval, scope, analysis, risk assessment, and ISMS design. ISO 27004 outlines how an organization can
monitor and measure security in relation to the ISO 27000 standards with
metrics. ISO 27005 defines the high
level risk management approach recommended by ISO and ISO 27006 outlines the
requirements for organizations that will measure ISO 27000 compliance for
certification.
User questions & answers