Home About Gamma  Tour our Web Site  Events  White Papers  Services  Visitors' Book  How to contact us
         IMS  Internal Control  ISMS  Smart Cards  Common Criteria
                 

Welcome to Gamma's index page on the international information security management standards.  Below you will find an overview of the standards and the navigation bar (left) will direct you to other pages that will tell you more.  Gamma's own management system is ISO/IEC 27001 certified (as well as being ISO 9001 certified) and we have a Fast Track ISMS Certification Methodology, using our revolutionary approach to risk assessment, to help you do the same.

Interested in Corporate Governance? Click here to find out  how ISO/IEC 27001:2005 fits in. Click here for our Fast Track and other ISMS services, or here for Integrated Management Systems
World map showing registrations by contiinent

ISMS Standards Overview

ISO/IEC 27001:2005 is a management standard, and explains how to build, maintain and improve an Information Security Management System (ISMS).  It is predicated on risk assessment and the Plan-Do-Check-Act model, which are two vital ingredients of corporate governance.  Thus, ISO/IEC 27001:2005 provides an excellent basis on which to build the management controls necessary to achieve an organisation’s mission, to manage risk, to assure effective control and to seek improvements where appropriate.  An ISMS forms part of an organisation's internal control system.

ISO/IEC 27002:2005 is a code of practice for information security management. It provides 133 information security guidelines structured under 11 major headings to enable readers to identify the security controls which are appropriate to their particular business or specific area of responsibility. As well as giving detailed security controls for computers and networks, ISO/IEC 27002 also provides guidance on security policy, staff security awareness, business continuity planning, and legal requirements. 

The ISMS standards are particularly pertinent to corporate governance in an "e-biz" context, where risk management not only has to contend with the usual risks of doing business

but also with rapidly changing IT/Internet risks and multiple legal jurisdictions. Thus the standards explain how to address the all-to-common and often devastating business impacts caused by viruses, web-site outages, improper disclosure of customer account details and incorrect pricing information.

A growing number of politicians and leaders of industry are now recognising the importance of these standards. Businesses, notably throughout Europe and Asia, who have a desire to flourish in the Information Age are already taking advantage of ISMS.  

Interested?

Click on the following for further details:

In order to buy a copy of the standards, please contact BSI Customer Services by telephone at (+44) 20 8996 7555 or go to https://eshop.bsi-global.com/.

             
             
             
 
Gamma is an ISO/IEC 27001:2005 and BS EN ISO 9001: 2000 registered company, certified for the provision of information security consultancy.  BSI certificate numbers IS 85916 and FS  30710.  Please send comments to webmaster@gammassl.co.uk or complete our Visitors'Book. Gamma Secure Systems, Diamond House, Frimley Road, Camberley, Surrey, GU15 2PS, UK Tel: +44 1276 702500 - Fax: +44 1276 692903Copyright © Gamma Secure Systems Limited 1998-2008
 
 
Page last updated: 17 March, 2008