• BS ISO/IEC 27010:2015

    Current The latest, up-to-date edition.

    Information technology. Security techniques. Information security management for inter-sector and inter-organizational communications

    Available format(s):  Hardcopy, PDF

    Language(s):  English

    Published date:  30-11-2015

    Publisher:  British Standards Institution

    Add To Cart

    Table of Contents - (Show below) - (Hide below)

    Foreword
    Introduction
    1 Scope
    2 Normative references
    3 Terms and definitions
    4 Concepts and justification
    5 Information security policies
    6 Organization of information security
    7 Human resource security
    8 Asset management
    9 Access control
    10 Cryptography
    11 Physical and environmental security
    12 Operations security
    13 Communications security
    14 System acquisition, development and maintenance
    15 Supplier relationships
    16 Information security incident management
    17 Information security aspects of business continuity
       management
    18 Compliance
    Annex A (informative) - Sharing sensitive information
    Annex B (informative) - Establishing trust in information
            exchanges
    Annex C (informative) - The Traffic Light Protocol
    Annex D (informative) - Models for organizing an information
            sharing community
    Bibliography

    Abstract - (Show below) - (Hide below)

    Gives guidelines in addition to the guidance given in the ISO/IEC 27000 family of standards for implementing information security management within information sharing communities.

    Scope - (Show below) - (Hide below)

    This International Standard provides guidelines in addition to the guidance given in the ISO/IEC27000 family of standards for implementing information security management within information sharing communities. This International Standard provides controls and guidance specifically relating to initiating, implementing, maintaining, and improving information security in inter-organizational and inter-sector communications. It provides guidelines and general principles on how the specified requirements can be met using established messaging and other technical methods. This International Standard is applicable to all forms of exchange and sharing of sensitive information, both public and private, nationally and internationally, within the same industry or market sector or between sectors. In particular, it may be applicable to information exchanges and sharing relating to the provision, maintenance and protection of an organization’s or nation state’s critical infrastructure. It is designed to support the creation of trust when exchanging and sharing sensitive information, thereby encouraging the international growth of information sharing communities.

    General Product Information - (Show below) - (Hide below)

    Committee IST/33/1
    Development Note Supersedes 11/30204593 DC. (04/2012) Supersedes 15/30320354 DC. (12/2015)
    Document Type Standard
    Publisher British Standards Institution
    Status Current
    Supersedes

    Standards Referenced By This Book - (Show below) - (Hide below)

    16/30330940 DC : 0 BS 10010 - INFORMATION CLASSIFICATION, MARKING AND HANDLING (ICMH) - SPECIFICATION
    BS 8587:2012 Guide to facility information management
    BS 10010:2017 Information classification, marking and handling. Specification

    Standards Referencing This Book - (Show below) - (Hide below)

    ISO/IEC 27001:2013 Information technology — Security techniques — Information security management systems — Requirements
    ISO/IEC 27006:2015 Information technology — Security techniques — Requirements for bodies providing audit and certification of information security management systems
    ISO/IEC 27002:2013 Information technology Security techniques Code of practice for information security controls
    ISO/IEC 27000:2016 Information technology Security techniques Information security management systems Overview and vocabulary
    • Access your standards online with a subscription

      Features

      • Simple online access to standards, technical information and regulations
      • Critical updates of standards and customisable alerts and notifications
      • Multi - user online standards collection: secure, flexibile and cost effective