ISO/IEC 27032, ISO 27032, Cyber Security, Information Security Management

ISO/IEC 27032 - Cyber Security

Information Security Management

ISO/IEC 27032:2012 provides guidance for improving the state of Cyber Security, drawing out the unique aspects of that activity and its dependencies on other security domains, in particular:

  • information security,
  • network security,
  • internet security, and
  • critical information infrastructure protection (CIIP).

ISO/IEC 27032 (ISO 27032) covers the baseline security practices for stakeholders in the Cyberspace. This International Standard provides:

  • an overview of Cybersecurity,
  • an explanation of the relationship between Cybersecurity and other types of security,
  • a definition of stakeholders and a description of their roles in Cybersecurity,
  • guidance for addressing common Cybersecurity issues, and
  • a framework to enable stakeholders to collaborate on resolving Cybersecurity issues.

Sections of ISO 27032

  • Section 0 : Overview
  • Section 1 : Assets in the Cyberspace
  • Section 2 : Threats against the security of the Cyberspace
  • Section 3 : Roles of stakeholders in Cybersecurity
  • Section 4 : Guidelines for stakeholders
  • Section 5 : Cybersecurity controls
  • Section 6 : Framework of information sharing and coordination
  • Section 7 : Annex A. Cyber Security readiness
  • Section 8 : Annex B. Additional resources
  • Section 9 : Annex C. Examples of related documents