ANSI/INCITS/IEC 27001-2005
View contents.
This International Standard has been prepared to provide a model for establishing, implementing, operating,monitoring, reviewing, maintaining and improving an Information Security Management System (ISMS). Theadoption of an ISMS should be a strategic decision for an organization. The design and implementation of anorganizations ISMS is influenced by their needs and objectives, security requirements, the processesemployed and the size and structure of the organization. These and their supporting systems are expected tochange over time. It is expected that an ISMS implementation will be scaled in accordance with the needs ofthe organization, e.g. a simple situation requires a simple ISMS solution.