In: Operations Management
choose one of the most dominant InfoSec management models, including national and international standards-based models. What makes this model one of the most dominant? What should be taken into consideration when selecting the most appropriate model or framework for an organization?
Answer-
One of the most dominant InfoSec management models is ISO 27002.
Throughout the years, since it was originally published under the
name British Standard BS7799, it has been one of the most widely
referenced Infosec management models. It was adopted as an
international standard framework for infosec in 200. It was revised
and renamed several times but today we know it as the
ISO/IEC2700:2013. The ISO 27002 was published in 2013 and it is the
newest version that includes 114 controls for many different
infosec related policies.
It was created in order to provide guidance to the management of
infosec professionals and their programs and organizations. It is
widely known but the most recent version is only available if
purchased. It includes controls and mechanisms designed to guide
infosec professionals in risk management. The ISO 27002 also
provides guidance in developing security standards and security
management. It was written to add practices that have come out
since the previous version ISO 27001.