A View of International It Security Standards, Especially ISO/IEC 17799

Bob Ashton · EDPACS · 2001

In late 2000, the International Organization for Standardization (ISO) published ISO/IEC [International Electrotechnical Commission]17799: 2000, Information Technology—Code of Practice for Information Security Management. The stated objective of ISO/IEC 17799: 2000 is to enable business enterprises to mitigate those IT threats that arise from physical disaster, fraud, and industrial espionage. (ISO/IEC 17799: 2000 can be ordered from the American National Standards Institute (ANSI)through the Internet at http://webstore.ansi.org/ansidocstore/product.asp?sku=ISO/IEC+1779:20009.The price is U.S.$112.)This article describes ISO/IEC 17799:2000 and some of the criticisms of it, provides a brief history of IT security standards, presents several of the more significant IT security standards, and, where appropriate, relates them to ISO/IEC 17799:2000.

Read the paper · More papers on PaperTik