Terms

Definitions that have been taken from ISO/IEC 27002:2005 are identified thus: *

Definitions that have been taken from ISO/IEC 27001:2005 are identified thus: **

Additional definitions that have been taken from BS7799-3:2006 are identified thus: ***

Definitions that have been taken from ISO/IEC 20000-1:2005 are identified thus: ****

Accreditation: the procedure through which an authoritative body formally recognises a person’s or organisation’s competence to carry out specified tasks. Not to be confused with certification. Third-party certification (auditing) bodies become accredited and those they audit, subject to a successful outcome, become certificated.

Asset: anything that has value to the organisation.* Information assets are likely ...

Get An Introduction to Information Security and ISO27001: A Pocket Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.