Category ISO Standards

ISO Standards Interpretation

ISO/IEC 27031:2011 — ICT Business Continuity

Guidelines for information and communication technology readiness for business continuity ISO/IEC 27031:2011 provides guidelines for the information and communication technology (ICT) readiness for business continuity within the broader context of organizational business continuity management (BCM). It bridges the gap between…

ISO/IEC 27032:2023 — Cybersecurity Guidelines

Guidelines for improving cybersecurity posture and managing cyber risks ISO/IEC 27032:2023 provides guidelines for improving an organization’s cybersecurity posture by addressing foundational aspects of cybersecurity — including the cybersecurity ecosystem, threat intelligence, attack surface management, and coordination among stakeholders. It…

ISO/IEC 27033-1:2015 — Network Security Overview

Network security — Part 1: Overview and concepts ISO/IEC 27033-1:2015 is the introductory part of the ISO/IEC 27033 series, providing an overview of network security concepts, architecture guidance, and management practices. It establishes the foundational terminology, principles, and framework used…

ISO/IEC 27019:2017 — ISMS for Energy Utilities

Code of practice for information security controls applied to energy utility industry ISO/IEC 27019:2017 provides interpretation and implementation guidance for information security controls applied to energy utility organizations — including electricity, gas, oil, and heat suppliers, as well as associated…

ISO/IEC 27014:2020 (2022) — Governance of Information Security

Strategic Oversight, Governance Principles, and the Evaluate-Direct-Monitor Cycle for Information Security ISO/IEC 27014:2020 (with its 2022 revision/amendment) establishes the governance framework for information security. Unlike operational standards such as ISO/IEC 27001 or 27002, which focus on the management and implementation…