Terms
Definitions that have been taken from ISO/IEC 27002:2005 are identified thus: *
Definitions that have been taken from ISO/IEC 27001:2005 are identified thus: **
Additional definitions that have been taken from BS7799-3:2006 are identified thus: ***
Definitions that have been taken from ISO/IEC 20000-1:2005 are identified thus: ****
Accreditation: the procedure through which an authoritative body formally recognises a person’s or organisation’s competence to carry out specified tasks. Not to be confused with certification. Third-party certification (auditing) bodies become accredited and those they audit, subject to a successful outcome, become certificated.
Asset: anything that has value to the organisation.* Information assets are likely ...
Get An Introduction to Information Security and ISO27001: A Pocket Guide now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.