<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-4338771713512166935</id><updated>2007-11-23T07:54:58.683-08:00</updated><title type='text'>ISO 27001 Report</title><link rel='alternate' type='text/html' href='http://www.27001.net/'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.27001.net/atom.xml'/><author><name>ISO 27001 Reporter</name></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>17</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-4390573436521580307</id><published>2007-11-23T06:10:00.000-08:00</published><updated>2007-11-23T07:54:58.712-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27031'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 22399'/><category scheme='http://www.blogger.com/atom/ns#' term='bs25999'/><category scheme='http://www.blogger.com/atom/ns#' term='bs25777'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><title type='text'>The ISO  22399 / PAS 22399 Dilemma</title><content type='html'>The business continuity story just gets stranger and stranger.  We have covered this previously, with respect to &lt;a href="http://www.27001.net/2007/07/iso-27000-iso-27031-and-business.html"&gt;ISO 27031&lt;/a&gt;. However, as events unfold the situation becomes ever more tangled.&lt;br /&gt;&lt;br /&gt;To recap, there are a host of developments with respect to business continuity and standardization:&lt;br /&gt;&lt;br /&gt;1) We have pondered where &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;BSI's&lt;/span&gt; useful looking business continuity management standard BS 25999-1 fits into the equation. Even with respect to their own standard set they also have a related publication PAS77, and are developing a standard BS 25777 from this. The second part of BS 25999 was in fact published this week, and as a specification, third party certification schemes will soon be in place.&lt;br /&gt;&lt;br /&gt;2) Even within ISO though, the water is as clear as mud. A new standard, &lt;a href="http://www.22399.info"&gt;ISO 22399&lt;/a&gt; (specifically ISO/PAS 22399) has just been published. This is a "Guideline for incident preparedness and operational continuity management".&lt;br /&gt;&lt;br /&gt;Great: so where does this (ISO22399) fit with respect to ISO 27031? And what about chapter 14 of ISO 27002? Or ISO 27001? Let alone all those developments over at &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;BSI&lt;/span&gt;, who seem far more advanced in the area.&lt;br /&gt;&lt;br /&gt;One might ask what exactly is going on here? How do all these developments relate? Do ISO  actually have any idea themselves?&lt;br /&gt;&lt;br /&gt;If they do in fact have a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;road map&lt;/span&gt; or overview of all these overlapping standards, it would be nice if they shared it with the public. Our guess is that no such document exists, which is rather bad news for standardization in this area.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/11/iso-22399-pas-22399-dilemma.html' title='The ISO  22399 / PAS 22399 Dilemma'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=4390573436521580307' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/4390573436521580307'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/4390573436521580307'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-8762475804556220488</id><published>2007-09-19T06:51:00.000-07:00</published><updated>2007-09-19T07:16:43.922-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso27k'/><category scheme='http://www.blogger.com/atom/ns#' term='iso27000'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><title type='text'>ISO 27000 Standard Groupings</title><content type='html'>Speculation has recently been rife regarding the future numbering system for the ISO 27000 series of standards. We know as a matter of fact the content areas of ISO 27001 through 27008. We also know about 27011, 27031, 27032, 27033 and 27799.&lt;br /&gt;&lt;br /&gt;Although everything else lacks any form of confirmation, there is a logic being frequently quoted which at least gives some credibility to the stories.&lt;br /&gt;&lt;br /&gt;The suggestion is that ISO 27010 through ISO 27019 will all cover information security within specific fields and industries. The following have in fact been quoted on a number of Spanish language websites:&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;ISO 27012: Guidelines for Finance&lt;/li&gt;   &lt;li&gt;ISO 27013: Guidelines for Manufacturing&lt;/li&gt;   &lt;li&gt;ISO 27015: Accreditation Guidelines&lt;/li&gt;   &lt;li&gt;ISO 27016: Auditing and Reviews&lt;/li&gt; &lt;/ul&gt; It is also suggested that ISO 27030 through ISO 27044 will cover the technical areas of information security, such as &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;cyber&lt;/span&gt; security, intrusion detection and trusted third party authentication.&lt;br /&gt;&lt;br /&gt;Again, there is some supporting evidence for this, but equally, nothing at all in the way of confirmation.&lt;br /&gt;&lt;br /&gt;If any reader of this log can clarify any of this, or provide additional information, please comment below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/09/iso-27000-standard-groupings.html' title='ISO 27000 Standard Groupings'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=8762475804556220488' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/8762475804556220488'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/8762475804556220488'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-4400675042127962037</id><published>2007-08-18T05:56:00.001-07:00</published><updated>2007-08-18T06:01:36.799-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27031'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27033'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27034'/><category scheme='http://www.blogger.com/atom/ns#' term='iso27k'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27032'/><title type='text'>ISO 2703n: Latest Developments</title><content type='html'>A little more has emerged on the emerging subset of ISO27k standards ISO27031-40. The following reflects the current position as we understand it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO/IEC 27031&lt;/span&gt;&lt;br /&gt;Information technology Information technology – Security Security techniques techniques - ICT readiness for business continuity&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO/IEC 27032&lt;/span&gt;&lt;br /&gt;Information technology - Security techniques - Guidelines for Cybersecurity (Suggested)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO/IEC 27033&lt;/span&gt;&lt;br /&gt;As referenced in previous articles, this is the revision of ISO 18028. It comprises seven distinct parts:&lt;br /&gt;&lt;br /&gt;ISO 27033-1&lt;br /&gt;Information technology Information technology – Security techniques Security techniques - Network security Network security – Guidelines for network security&lt;br /&gt;&lt;br /&gt;ISO 27033-2&lt;br /&gt;Information technology Information technology – Security techniques Security techniques - Network security Network security – Guidelines for the design and implementation of network&lt;br /&gt;&lt;br /&gt;ISO 27033-3&lt;br /&gt;IT network security - Reference networking scenarios - Risks, design, technologies and control issues&lt;br /&gt;&lt;br /&gt;ISO 27033-4&lt;br /&gt;IT network security - Security network information with network security gateways - Risks, design techniques and control issues&lt;br /&gt;&lt;br /&gt;ISO 27033-5&lt;br /&gt;IT network security - Secure remote access - Risks, design techniques and control issues&lt;br /&gt;&lt;br /&gt;ISO 27033-6&lt;br /&gt;IT network security - Securing communications across networks using Virtual Private Networks&lt;br /&gt;&lt;br /&gt;ISO 27033-7&lt;br /&gt;IT network security - Guidelines for the design and implementation of network security&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO/IEC 27034 &lt;/span&gt;&lt;br /&gt;Information technology Information technology –Security techniques Security techniques - Guidelines for application security&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;These at are various stages of the publication process, with at least one still at the proposal stage.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/08/iso-2703n-latest-developments.html' title='ISO 2703n: Latest Developments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=4400675042127962037' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/4400675042127962037'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/4400675042127962037'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-2080105333045849499</id><published>2007-07-19T01:21:00.000-07:00</published><updated>2007-07-19T02:29:12.034-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso27002'/><category scheme='http://www.blogger.com/atom/ns#' term='iso'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27002'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 17799'/><title type='text'>ISO 17799 to ISO 27002: A Warning</title><content type='html'>It is well known that ISO 17799 has been renamed to ISO 27002. This was confirmed by the appropriate ISO Technical Committee some weeks ago.&lt;br /&gt;&lt;br /&gt;A number of people questioned the need for this, and have asked why this couldn't wait until the next upgrade of the standard. Nonetheless, it went ahead, and we waited for the renamed copy to be made available.&lt;br /&gt;&lt;br /&gt;Here is the crux though: ISO have now made this available... BUT.... it is simply ISO 17799:2005 with a single accompanying PDF sheet stating "Replace '17799' with '27002'". Seriously, that is it!&lt;br /&gt;&lt;br /&gt;So the warning is that if you already have a copy of ISO 17799:2005 and were thinking of buying another copy to replace it, &lt;span style="font-weight: bold;"&gt;don't&lt;/span&gt;, unless the situation changes (and it may not).&lt;br /&gt;&lt;br /&gt;If you don't have a copy of ISO 17799:2005 and were thinking of buying a copy of ISO 27002, go for ISO 17799:2005 instead if you can find that cheaper than ISO offer it for (and you can), unless the situation changes (and it may not).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We will continue to monitor the situation and will immediately post any changes which we identify.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/07/iso-17799-to-iso-27002-warning.html' title='ISO 17799 to ISO 27002: A Warning'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=2080105333045849499' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/2080105333045849499'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/2080105333045849499'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-6762056149011458715</id><published>2007-07-16T14:33:00.000-07:00</published><updated>2007-07-16T14:42:33.370-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27033'/><category scheme='http://www.blogger.com/atom/ns#' term='iso27000'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><title type='text'>And Another Emerges: ISO 27033</title><content type='html'>The next ISO 27000 series standard is on the starting block: ISO 27033.&lt;br /&gt;&lt;br /&gt;On 12th July a formal note was distributed by the appropriate ISO committee (JTC 1 / SC 27) announcing a letter ballot for early revision and renumbering (to 27033) of existing standard  18028.&lt;br /&gt;&lt;br /&gt;Obviously, this is the very start of a lengthy process, but the note also revealed the proposed structure of the new standard, which it is proposed would comprise seven parts:&lt;br /&gt;&lt;br /&gt;1. Guidelines for network security&lt;br /&gt;2. Guidelines for design/implementation of network security&lt;br /&gt;3. Reference networking scenarios&lt;br /&gt;4. Securing communications between networks using gateways&lt;br /&gt;5. Securing remote access&lt;br /&gt;6. Securing communications across networks using VPNs&lt;br /&gt;7. Guidelines for securing&lt;br /&gt;&lt;br /&gt;Momentum for the series continues to increase.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/07/and-another-emerges-iso-27033.html' title='And Another Emerges: ISO 27033'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=6762056149011458715' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/6762056149011458715'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/6762056149011458715'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-7405385960319213425</id><published>2007-07-10T05:10:00.000-07:00</published><updated>2007-07-10T05:14:37.048-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hipaa'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27799'/><category scheme='http://www.blogger.com/atom/ns#' term='iso27789'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27789'/><category scheme='http://www.blogger.com/atom/ns#' term='iso27799'/><title type='text'>Update On ISO 27799: ISO 27789?</title><content type='html'>ISO 27799 will be the health sector specific version of ISO 17799/27002. The above though is a bit of a misleading title, because it is still under approval and there is no 'update' at all!&lt;br /&gt;&lt;br /&gt;However, whilst scanning the airways for progress we identified another health sector related ISO 27000 standard. This is ISO 27789. Like ISO27799 it is specific to the health sector. Its provisional title is: Audit trails for electronic health records. The planned publication date is late 2009.&lt;br /&gt;&lt;br /&gt;It looks therefore like the ISO 277nn prefix may have been bagged by the health sector.&lt;br /&gt;&lt;br /&gt;TO WATCH:&lt;br /&gt;In the US, the relationship between ISO27799 and HIPAA (Health Insurance Portability and Accountability Act). Will HIPAA become a driver for the adoption of ISO 27799? Will 27799 be used as an example of due diligence with respect to certain aspects of the act? Time will tell.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/07/update-on-iso-27799-iso-27789.html' title='Update On ISO 27799: ISO 27789?'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=7405385960319213425' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/7405385960319213425'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/7405385960319213425'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-5436600238797665042</id><published>2007-07-10T05:08:00.000-07:00</published><updated>2007-07-10T05:09:56.471-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso27000'/><title type='text'>ISO27000 Interviews</title><content type='html'>We are planning a series of short interviews with leading industry figures. These will be posted from this page as and when they are published.&lt;br /&gt;&lt;br /&gt;The list of early contenders is currently being drawn up. We will then approach the lucky interviewees!&lt;br /&gt;&lt;br /&gt;Please return to this page for more information.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/07/iso27000-interviews.html' title='ISO27000 Interviews'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=5436600238797665042' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/5436600238797665042'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/5436600238797665042'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-1859553613879310422</id><published>2007-07-04T07:21:00.002-07:00</published><updated>2007-07-04T07:25:47.423-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bs7799'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27005'/><category scheme='http://www.blogger.com/atom/ns#' term='iso27000'/><category scheme='http://www.blogger.com/atom/ns#' term='bs31100'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 31000'/><title type='text'>How is ISO27000 Related to ISO 31000 And BS31100?</title><content type='html'>The answer is: we don't know! So why ask the question? Because it probes the relationship between different aspects of risk assessment, and different sets of standards.&lt;br /&gt;&lt;br /&gt;We tripped upon two holding sites: one for &lt;a href="http://www.31000.net/"&gt;ISO 31000&lt;/a&gt; and one for &lt;a href="http://www.bs31100.info/"&gt;BS31100&lt;/a&gt;. Scratching the surface with both &lt;a href="http://www.iso.ch/"&gt;ISO&lt;/a&gt; and &lt;a href="http://www.bsi-global.com/"&gt;BSI&lt;/a&gt; didn't reveal too much extra. However, it does appear that these BOTH address risk management at a corporate/organizational level. Security risk assessment is part of this, but only part of it.&lt;br /&gt;&lt;br /&gt;Why 31000 and 31100? Clearly this similarity indicates SOME relationship and forethought, but at this stage we could not determine specifically what this was. It does appear that BS31100 is much closer to fruition than ISO31000, but how they are related will be interesting to determine, as will the scope for BS31100 to become ISO 31100 or perhaps ISO 31001.&lt;br /&gt;&lt;br /&gt;The precise relationship between these and BS7799-3, and/or ISO27005, will also be interesting to see. There will surely be cross reference between these, as there are logical relationships between them. How much further that goes remains to be seen.&lt;br /&gt;&lt;br /&gt;This does illustrate however that it isn't just the ISO2700 series which is 'shrouded in mystery', but others too. For those of us who thrive on clarity, it is a bit of a nightmare!</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/07/how-is-iso27000-related-to-iso-31000.html' title='How is ISO27000 Related to ISO 31000 And BS31100?'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=1859553613879310422' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/1859553613879310422'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/1859553613879310422'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-3899795458672828393</id><published>2007-07-04T07:21:00.001-07:00</published><updated>2007-07-04T07:24:19.603-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><title type='text'>The 27000 Who's Who</title><content type='html'>This is another ongoing project. Over time we will build up a comprehensive "Who's Who" of the ISO 27000 world. The current list is below:&lt;br /&gt;&lt;br /&gt;David Watson&lt;br /&gt;The very first BS7799/ISO17799/ISO27001 (take your pick) auditor. David Watson is still busy in the infosec arena, owning a consultancy company in the UK and moderating the Dr Watson forum on the ISO 17799/27001 Community. He is also an accomplished author.&lt;br /&gt;&lt;br /&gt;Kate Hartley&lt;br /&gt;The driving force behind the biggest online user group dedicated to the standards (17799.com)&lt;br /&gt;&lt;br /&gt;Ted Humphreys&lt;br /&gt;A long established consultant, Ted Humphreys has been a key player in the development of the standards, and holds a pivotal role on the relevant ISO technical committee.&lt;br /&gt;&lt;br /&gt;Gary Hinson&lt;br /&gt;Gary a consultant and is ISSA's UK Secretary. He also runs several websites, including a very easy to read blog (noticebored.com).&lt;br /&gt;&lt;br /&gt;Andrew Smith&lt;br /&gt;A policy writer and consultant, but best known as the moderator of the major Yahoo user groups.&lt;br /&gt;&lt;br /&gt;Brian Doswell&lt;br /&gt;Manages a consultancy practice and is a member of BCI's advisory board. Brian is also a published (ISO 17799) information security author.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This of course is an initial seed list, which will be added to. Please add your own suggestions via the comment option below.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/07/27000-whos-who.html' title='The 27000 Who&apos;s Who'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=3899795458672828393' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/3899795458672828393'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/3899795458672828393'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-5050863884436089662</id><published>2007-07-02T02:58:00.000-07:00</published><updated>2007-07-02T04:02:47.384-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso27031'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27031'/><category scheme='http://www.blogger.com/atom/ns#' term='bs25999'/><category scheme='http://www.blogger.com/atom/ns#' term='bs25777'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><title type='text'>ISO 27000: ISO 27031 and Business Continuity Numbering</title><content type='html'>The assignment of numbers within the ISO 27000 series has been the subject of ongoing debate for some time. The confusion with respect to future intentions is no better exemplified than with respect to business continuity.&lt;br /&gt;&lt;br /&gt;ISO 27031 has long been understood to be earmarked for at least one aspect of business continuity. Clarity was been a long time in coming, but it does now appear that this number will be assigned to a standard pertaining to ICT Readiness for Business Continuity, based perhaps upon SS507. Or does it? Confirmation can still not be found on the ISO website.&lt;br /&gt;&lt;br /&gt;If ISO27031 is to be assigned to ICT, then what about other aspects of business continuity? If ICT readiness fits under the ISO 27000 billing, what about planning or service continuity?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Other Business Continuity Standards&lt;/span&gt;&lt;br /&gt;BS25999 is currently setting about filling the void for business continuity planning (BCP). This is interesting because its structure is the same as ISO standards tend to be: a code of practice and a specification. BS25999-1 is the code of practice. BS25999-2 is the specification.&lt;br /&gt;&lt;br /&gt;Does that sound familiar? It should do. Think ISO 27001 and ISO 27002. Think the two parts of ISO 20000. The list is rather long.&lt;br /&gt;&lt;br /&gt;So if 25999 is to evolve to be an ISO standard, where does that fit in the 27000 numbering system?&lt;br /&gt;&lt;br /&gt;It doesn't end here. What about PAS77? This BSI document relates to IT service continuity, which is part of the ISO 20000 scene. It is aligned with that standard. Unofficial word has it that this is to become a BS standard (this site: &lt;a href="http://www.bs25777.info/"&gt;BS25777.Info&lt;/a&gt; - is a bit of a giveaway). So where is this to fit if it evolves into the ISO system? It is hard to imagine that ISO will not embrace such a standard given the success of ISO 20000.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We have heard a number of rumours with respect to business continuity numbering, but repeating them probably wouldn't serve a positive purpose at this time. A little more clarity from ISO might, however.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/07/iso-27000-iso-27031-and-business.html' title='ISO 27000: ISO 27031 and Business Continuity Numbering'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=5050863884436089662' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/5050863884436089662'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/5050863884436089662'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-3310996368545867373</id><published>2007-07-01T03:23:00.000-07:00</published><updated>2007-07-02T04:05:53.644-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso27001 certification'/><category scheme='http://www.blogger.com/atom/ns#' term='iso27001'/><title type='text'>The Official ISO27001 Certification Register</title><content type='html'>We frequently see questions asked regarding this issue, largely as people search for data regarding existing certifications, or perhaps to get an idea of the total number of certificates issued.&lt;br /&gt;&lt;br /&gt;There simply is no official worldwide register.&lt;br /&gt;&lt;br /&gt;Searching the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;internet&lt;/span&gt; reveals a couple of efforts to build credible registers, but in truth these are sourced by a very tiny minority of certification bodies. They are thus not even remotely complete.&lt;br /&gt;&lt;br /&gt;The most interesting approach is the one adopted by the ISO17799/27001 Guide, which is a dedicated Wiki. This operates a voluntary register, which enables certified organizations to enter their own details. This is surely the most valid approach.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Voluntary v Involuntary&lt;/span&gt;&lt;br /&gt;Not every certified organization wants its details paraded on the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;internet&lt;/span&gt;. There may be a variety of reasons for this.&lt;br /&gt;&lt;br /&gt;For example, there is a school of thought which believes that specifying in public which security framework has been followed is in itself something of a security risk. If something is missing from that framework, then it is quite possible that it is missing from the security implementation too, and stating this in public is not sensible. Another example could be the loss of competitive advantage if the certification of part of an organization is made public in the circumstance in which others are to follow shortly.&lt;br /&gt;&lt;br /&gt;Whatever the reason, however, surely the certified organization should be the party to determine when, where and whether this is made public. A voluntary arrangement supports this proposition.&lt;br /&gt;&lt;br /&gt;It has to be accepted that this approach will never create a complete register, but at least the playing field will be level and equal, and not driven by selected certification bodies.&lt;br /&gt;&lt;br /&gt;The voluntary register is a worthy initiative.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/07/official-iso27001-certification.html' title='The Official ISO27001 Certification Register'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=3310996368545867373' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/3310996368545867373'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/3310996368545867373'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-8968425795784986850</id><published>2007-06-30T10:12:00.000-07:00</published><updated>2007-07-02T04:07:58.479-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27001 implementation'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27001'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><title type='text'>The Benefits of ISO 27001 Implementation</title><content type='html'>The benefits of standardization, and of implementation of one or more of the ISO 27000 series are wide and varied. Although they tend to differ from organization to organization, many are common.&lt;br /&gt;&lt;br /&gt;The following is a list of potential benefits. As with many items on this website, this is an ongoing project. Please feel free to add further points via the comments option below.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Interoperability&lt;/span&gt;&lt;br /&gt;This is a general benefit of standardization. The idea is that systems from diverse parties are more likely to fit together if they follow a common guideline.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Assurance&lt;/span&gt;&lt;br /&gt;Management can be assured of the quality of a system, business unit, or other entity, if a recognized framework or approach is followed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Due Diligence&lt;/span&gt;&lt;br /&gt;Compliance with, or certification against, and international standard is often used by management to demonstrate due diligence.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bench Marking&lt;/span&gt;&lt;br /&gt;Organizations often use a standard as a measure of their status within their peer community. It can be used as a bench mark for current position and progress.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Awareness&lt;/span&gt;&lt;br /&gt;Implementation of a standard such as ISO 27001 can often result in greater security awareness within an organization.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Alignment&lt;/span&gt;&lt;br /&gt;Because implementation of ISO 27001 (and the other ISO 27000 standards) tends to involve both business management and technical staff, greater IT and Business alignment often results.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/06/benefits-of-iso-27001-implementation.html' title='The Benefits of ISO 27001 Implementation'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=8968425795784986850' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/8968425795784986850'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/8968425795784986850'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-2095544632601569547</id><published>2007-06-30T08:40:00.001-07:00</published><updated>2007-06-30T08:50:19.055-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27001'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><title type='text'>Talking About ISO 27001</title><content type='html'>A number of forums have emerged over the years to enable peer to peer communiction and dialogue on ISO 27001 and the other ISO 27000 standards.&lt;br /&gt;&lt;br /&gt;The major ones are as follows:&lt;br /&gt;&lt;br /&gt;The ISO 17799 and 27001 Community Portal&lt;br /&gt;(17799.com)&lt;br /&gt;This is the oldest and the biggest, with around 2,000 members&lt;br /&gt;&lt;br /&gt;Yahoo ISO 17799&lt;br /&gt;(tech.groups.yahoo.com/group/iso17799security/)&lt;br /&gt;Whilst not the biggest, this is probably the busiest&lt;br /&gt;&lt;br /&gt;Yahoo ISO 27001&lt;br /&gt;(tech.groups.yahoo.com/group/iso-27001/)&lt;br /&gt;Similar to the other Yahoo group, but focused entirely upon ISO 27001&lt;br /&gt;&lt;br /&gt;Google Group ISO 27001 Security&lt;br /&gt;(groups.google.com/group/iso27001security)&lt;br /&gt;Directed at the ISO 27000 series.&lt;br /&gt;&lt;br /&gt;Google Group ISO 27001&lt;br /&gt;(groups.google.com/group/ISO-27001)&lt;br /&gt;This is related to the ISO 27001 newsletter&lt;br /&gt;&lt;br /&gt;MSN ISO 27000 Group&lt;br /&gt;(groups.msn.com/27000UserGroup/)&lt;br /&gt;This covers all of the ISO 2700 series.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Have we missed any? Probably. If you know of any not listed above, please let us know via the comment function.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/06/talking-about-iso-27001.html' title='Talking About ISO 27001'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=2095544632601569547' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/2095544632601569547'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/2095544632601569547'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-2622925995730616090</id><published>2007-06-30T08:21:00.000-07:00</published><updated>2007-06-30T08:34:10.816-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27031'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27005'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27799'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27006'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27001'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27007'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27004'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27003'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27002'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27000'/><title type='text'>ISO 27000: Where Are We?</title><content type='html'>The ISO 27000 series of information security standards is a moving feast. This is a 'live page' which will be kept current with the latest situation as we understand it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27000&lt;/span&gt;&lt;br /&gt;Not yet published. It will define vocabulary and definitions for the rest of the series.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27001&lt;/span&gt;&lt;br /&gt;Published. This is the specification for an ISMS&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27002&lt;/span&gt;&lt;br /&gt;Awaiting publication. This will be the rename of ISO 17799.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27003&lt;/span&gt;&lt;br /&gt;Not yet published. This will be an implementation guide.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27004&lt;/span&gt;&lt;br /&gt;Not yet published. This will cover measurement and metrics for information security management.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27005&lt;/span&gt;&lt;br /&gt;Not yet published. This will cover information security risk management, and is likely to be based upon BS7799-3.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27006&lt;/span&gt;&lt;br /&gt;Published. This is a formal guide to the certification and registration process.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27007&lt;/span&gt;&lt;br /&gt;Not yet published. This will cover the audit process for an ISMS&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27031&lt;/span&gt;&lt;br /&gt;Not yet published. This standard will cover ICT business continuity planning.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27032&lt;/span&gt;&lt;br /&gt;Not yet published. This is currently a proposed standard for internet security.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISO 27799&lt;/span&gt;&lt;br /&gt;Awaiting publication. This will be the first industry specific version of ISO 27002. It is focused upon the health sector.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/06/iso-27000-where-are-we.html' title='ISO 27000: Where Are We?'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=2622925995730616090' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/2622925995730616090'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/2622925995730616090'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-1491515500649791669</id><published>2007-06-30T08:13:00.000-07:00</published><updated>2007-06-30T08:19:54.108-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27002'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 17799'/><title type='text'>ISO 27002 Status</title><content type='html'>There is no real rush: ISO 27002 is simply the re-publication of ISO 17799, but with a different name. Why this is deemed necessary as an interim publication, rather than at the next upgrade, is unclear. However, the momentum behind the ISO 27000 series concept has driven the decision in this direction.&lt;br /&gt;&lt;br /&gt;The original intention was to rename ISO 17799 in April 2007. Due to several factors, this did not occur. The decision to press ahead though was endorsed in May at a meeting of the appropriate ISO sub-committee (SC 27).&lt;br /&gt;&lt;br /&gt;Despite this, a search of all the major internet webstores and a scan of the websites of the standard bodies indicates that ISO 27002 is still not available.&lt;br /&gt;&lt;br /&gt;We will update this post when this position changes.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/06/iso-27002-status.html' title='ISO 27002 Status'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=1491515500649791669' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/1491515500649791669'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/1491515500649791669'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-7500474834707387288</id><published>2007-06-30T07:57:00.000-07:00</published><updated>2007-06-30T08:09:46.445-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iso 27001 certification'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27001'/><title type='text'>What Is ISO 27001?</title><content type='html'>In a nutshell it is an ISO standard specifying the requirements for an information security management system. It was published in October 2005, and was based heavily upon the British Standard, BS 7799-2.&lt;br /&gt;&lt;br /&gt;ISO/IEC 27001 is often considered to be the prime ISO 27000 standard because it is this against which certification can be sought. It is aligned with other ISO quality management standards, such as ISO 9001 and ISO 14001.&lt;br /&gt;&lt;br /&gt;The standard is also intended to drive the selection of adequate and proportionate security controls. Hence the relationship with ISO 27002, which defines individual controls within a code of practice framework.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/06/what-is-iso-27001.html' title='What Is ISO 27001?'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=7500474834707387288' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/7500474834707387288'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/7500474834707387288'/><author><name>ISO 27001 Reporter</name></author></entry><entry><id>tag:blogger.com,1999:blog-4338771713512166935.post-3936110301259947470</id><published>2007-06-30T07:49:00.000-07:00</published><updated>2007-07-02T04:11:52.505-07:00</updated><title type='text'>ISO 27001 Report: The Mission</title><content type='html'>The first day and the first post: &lt;span style="font-style: italic;"&gt;ISO 27001 Report&lt;/span&gt; has been created.&lt;br /&gt;&lt;br /&gt;This informational newslog is dedicated to ISO 27001 and related standards and topics. It will offer both information and prespective on both this ISMS standard, and the rest of the ISO 27000 series.&lt;br /&gt;&lt;br /&gt;In addition to reporting recent events (the news function), we will strive to document the standard(s) and provide ongoing information on implementation, including certification. This will be framed within a wider information security setting.&lt;br /&gt;&lt;br /&gt;Hopefully you will enjoy reading the log as much as we will enjoy creating it.&lt;br /&gt;&lt;br /&gt;Thank you for visiting us.</content><link rel='alternate' type='text/html' href='http://www.27001.net/2007/06/iso-27001-report-mission.html' title='ISO 27001 Report: The Mission'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4338771713512166935&amp;postID=3936110301259947470' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.27001.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/3936110301259947470'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4338771713512166935/posts/default/3936110301259947470'/><author><name>ISO 27001 Reporter</name></author></entry></feed>