4. Normative aspects
In the field of IT security, as is the case for all innovative industrial activities, dedicated standards have been developed in parallel with practical development, and have evolved in a mutually influential way: feedback from the field has influenced standards, but standardization has also facilitated the transition to practice. This evolution is still ongoing, as the field is not yet technically stabilized.
With regard to cybersecurity, the ISO 27001 standard, derived from BS 7799, was introduced in 2005, enabling certification of an "Information Security Management System" (ISMS). The ISO 2700x family was extended in June 2009 with ISO 27005, which provides a methodology for identifying and assessing risks to information assets, and in 2013 with ISO 27032, which provides guidelines for cybersecurity.
Common Criteria standards (ISO 15408,...
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!
Normative aspects
Article included in this offer
"Safety and risk management"
(
459 articles
)
Updated and enriched with articles validated by our scientific committees
A set of exclusive tools to complement the resources
Bibliography
Bibliography
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!