Clause 2: Normative References
Normative References are prescribed and must be adhered to in order to meet the standard’s requirements. ISO 27001 Clause 2 Normative References holds lists, which are the enforced standards or documents cited within ISO 27001 and are essential for its application.
List Of ISO 27001 Clause 2 Normative References
- An overview of information security management systems and definition of the terms and concepts used in ISO 27001 are offered by the ISO/ICE 27000.
- Code of practice for information security controls, offers a comprehensive set of measures to safeguard information are served by the ISO/IEC 27002.
- The standard of guidance on establishing an information security management system which includes the procedure of its planning, designing, and implementation of the ISMS which covers under the ISO/IEC 27003.
- The guidance on evaluating the effectiveness of an information security management system and offers recommendations for creating and utilizing security metrics which are provided by ISO/IEC 27004.
- The guidance on managing processes for identifying, assessing, and addressing security risks which are offered in the ISO/IEC 27005 information security risks.
- Outlining the requirements and guidance for organizations seeking certification of their information security management systems under ISO 27001 is provided by ISO/IEC 27006 standard.
- Implementing information security management in healthcare organizations, aligning with the requirements of ISO 27001 these guidelines are offered by ISO/IEC 27799.
- Establishing a privacy framework for safeguarding personal data/information and providing guidance on managing privacy risks under the standard ISO/IEC 29100.
The normative references help in aligning ISO 27001 with internationally recognized standards and best practices, allows organizations in establishing a strong and comprehensive information security management system. By incorporating the above standards, ISO 27001 provides a structured approach for organizations in managing and safeguarding their information assets effectively.
