错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ISO/IEC 27001 Standard: Analytical and Comparative Overview

  • Afnan A. Alrehili,
  • Omar H. Alhazmi

摘要

The process of digital transformation exposes organizations to cybersecurity threats and numerous vulnerabilities. As these threats and attacks become increasingly sophisticated, the need for effective security measures to protect valuable assets and maintain confidence in the digital environment has become even more critical. Adopting an Information Security Management System (ISMS) assists organizations in achieving effective governance in relation to information security and business continuity. Among the numerous security standards available (e.g., NIST CSF, COBIT, and PCI DSS), ISO 27001 is one of the most highly adopted security frameworks. Security standards differ from each others in their requirements, policies, and best practices, which makes it the responsibility of decision-makers to choose the appropriate one based on the specific needs and objectives of their organizations. This paper aims to provide an overview of the structure and components of ISO 27001 and how it evolves over time. Furthermore, a comparison between ISO 27001 and two other popular security standards, NIST CSF and COBIT, is provided.