International Security Standards
Virgilio Viegas, Oben Kuyucu · Apress eBooks · 2022
Organizations must increasingly demonstrate to their customers and regulatory authorities that they have sufficient protection, security, resilience, and privacy of their information, assets, and systems, based on best practices. International information security standards applicable for all organizations such as ISO 27000 series or industry-specific information security standards such as PCI DSS and SWIFT were created for that reason. When organizations show their compliance to these standards, their customers acknowledge that they understand their risks, perform risk mitigation actions, create baseline security, and manage the risk on their systems. This does not mean that compliant organizations are free of risks or vulnerabilities, but they certainly have a better security posture than non-compliant organizations.