Clause 2: Normative References

Normative References are prescribed and must be adhered to in order to meet the standard’s requirements. ISO 27001 Clause 2 Normative References holds lists, which are the enforced standards or documents cited within ISO 27001 and are essential for its application.

List Of ISO 27001 Clause 2 Normative References

  • An overview of information security management systems and definition of the terms and concepts used in ISO 27001 are offered by the ISO/ICE 27000.
  • Code of practice for information security controls, offers a comprehensive set of measures to safeguard information are served by the ISO/IEC 27002.
  • The standard of guidance on establishing an information security management system which includes the procedure of its planning, designing, and implementation of the ISMS which covers under the ISO/IEC 27003.
  • The guidance on evaluating the effectiveness of an information security management system and offers recommendations for creating and utilizing security metrics which are provided by ISO/IEC 27004.
  • The guidance on managing processes for identifying, assessing, and addressing security risks which are offered in the ISO/IEC 27005 information security risks.
  • Outlining the requirements and guidance for organizations seeking certification of their information security management systems under ISO 27001 is provided by ISO/IEC 27006 standard.
  • Implementing information security management in healthcare organizations, aligning with the requirements of ISO 27001 these guidelines are offered by ISO/IEC 27799.
  • Establishing a privacy framework for safeguarding personal data/information and providing guidance on managing privacy risks under the standard ISO/IEC 29100.

The normative references help in aligning ISO 27001 with internationally recognized standards and best practices, allows organizations in establishing a strong and comprehensive information security management system. By incorporating the above standards, ISO 27001 provides a structured approach for organizations in managing and safeguarding their information assets effectively.