
The ISO/IEC 27000 family of information security management standards (ISMS), also known as the 'ISO27K', is a series consisting of information security standards published together by ISO and the International Electrotechnical Commission (IEC).
About the Standard
Nowadays, information plays a crucial part in many business products and processes from payroll information to company secret. Management of information becomes intricate as organizations are surrounded by a wide range of confidential information which requires effective protection against the growing threat from cyber-thieves, hackers, and accidental breaches.
International Organization for Standardization (ISO) establishes a globally recognized ISO/IEC 27001 standard and defines the requirements for establishment, implementation, documentation, and improvement of ISMS. With ISMS, the organization implementing this standard could close loopholes within information securities related processes, people, technology, and organization, and reduce information securities risks. This consequentially strengthens information security in three key areas, i.e., confidentiality, integrity, and availability.
ISO/IEC 27000 Series
The ISO/IEC 27000 family of information security management standards (ISMS), also known as the 'ISO27K', is a series consisting of information security standards published together by ISO and the International Electrotechnical Commission (IEC). The series provides guidelines and recommendations on information security management through information security controls within the context of ISMS. The standards in the family can be integrated to deliver best-practice information security management to the organization that implements the standards.
Key Family Standards for Certification
Type of audit
Advantages of ISO/IEC 27001 and Its Series Certification
Certification Audit Process
1. Request for A Proposal
a. Company interested in certifying against ISO/IEC 27001 requests for a proposal from TUV NORD Thailand
2. Certification Audit
a. Stage 1: Documentation Review
b. Stage 2: On-site Verification
3. Issue of ISO/IEC 27001 Certificate
4. Surveillance Audit 1 & 2 (within the next 2 years after the certificate is issued)
5. Re-certification within the next 3 years after the certificate issued.
Highlights of 2022 Version