ISO/IEC 27001:2005 covers all types of organizations including commercial enterprises, government agencies, not-for profit organizations. The standard specifies the requirements for establishing, operating, and maintaining a well documented Information Security Management System within the context of the organization's overall business risks. It also states the requirements for the execution of security controls customized to the needs of individual organizations. ISO/IEC 27001:2005 is well suited for several purposes, including:
Use within organizations to devise security standards and objectives
Use within organizations as a means to guarantee that security risks are minimum and cost effective
Use within organizations to ensure conformity with local and international laws and regulations
Use within an organization as framework for the execution and administration of controls to ensure that the security objectives are met
Identification of existing information security management activities
Determination of the status of information security management processes
Use by the auditors to determine compliance with the set policies and directives
Use by organizations to provide information about information security standards
Management Systems Certification Services Offered By FQC Certification Pvt. Ltd.: ISO 9001: 2008 Quality Management System Certification.
More details:View company website
Its Free
Verify Now