Original Source: ISO
This International Standard is designed for organizations to use as a reference for selecting controls within the process of implementing an Information Security Management System (ISMS) based on ISO/IEC 27001[10] or as a guidance document for organizations implementing commonly accepted information security controls. This standard is also intended for use in developing industry- and organization-specific information security management guidelines, taking into consideration their specific information security risk environment(s)…
Contributors: ISOCategories: SIG U Resource, Tool
SRC Type: Risk Management, Sourcing Management, Third Party Management