Historical

INCITS/ISO/IEC 27005:2011[2012]

Information technology - Security techniques - Information security risk management

ISO/IEC 27005:2011 provides guidelines for information security risk management.

It supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach.

Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 and ISO/IEC 27002 is important for a complete understanding of ISO/IEC 27005:2011.

ISO/IEC 27005:2011 is applicable to all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations) which intend to manage risks that could compromise the organization's information security.

CONTENT PROVIDER
InterNational Committee for Information Technology Standards [incits]

Others Also Bought
Risk management - Principles and guidelines
Included in Packages
This standard is not included in any packages.
Document History
Amendments & Corrections
We have no amendments or corrections for this standard.