CICRA has lead auditors in ISO 27000 series and a team of experts with international exposure who can supervise and lead your organization to achieve ISO 27001 standards. They will also provide post-standard consultations and testing for your organization.CICRA will also help your organization to achieve ISO standards in all 27000 series.
The ISO 27000 series of standards have been specifically reserved by ISO for information security matters. This of course, aligns with a number of other topics, including ISO 9000 (quality management) and ISO 14000 (environmental management).
ISO 27000 series will be populated with a range of individual standards and documents. A number of these are already well known, and indeed, have been published. Others are scheduled for publication, with final numbering and publication details yet to be determined.
At present, twenty-three of the standards in the series are published and available, while several more are still under development. The original ISO/IEC standards are sold directly by ISO, while sales outlets associated with various national standards bodies also sell various versions including local translations.
The ISO/IEC 27000-series
The ISO/IEC 27000-series (also known as the ‘ISMS Family of Standards’ or ‘ISO27k’ for short) comprises information security standards published jointly by the International Organization for Standardization (ISO) and the International Electro-technical Commission (IEC).
The series provides best practice recommendations on information security management, risks and controls within the context of an overall information security management system (ISMS), similar in design to management systems for quality assurance (the ISO 9000 series) and environmental protection (the ISO 14000 series).
The series is deliberately broad in scope, covering more than just privacy, confidentiality and IT or technical security issues. It is applicable to organizations of all shapes and sizes. All organizations are encouraged to assess their information security risks, then implement appropriate information security controls according to their needs, using the guidance and suggestions where relevant. Given the dynamic nature of information security, the ISMS concept incorporates continuous feedback and improvement activities, summarized by Deming’s “plan-do-check-act” approach, that seek to address changes in the threats, vulnerabilities or impacts of information security incidents.
The standards are the product of ISO/IEC JTC1 (Joint Technical Committee 1) SC27 (Subcommittee 27), an international body that meets in person twice a year.
Key initiative in partnership with Australia’s top-ranked Deakin University Six million cyber security job openings by 2019 CICRA Campus, the pioneering cyber security training provider, in partnership with Australia’s top-ranked Deakin University, is introducing the first Bachelor of Cyber Security degree in Sri Lanka. “Parents should consider a cyber security degree for their ambitious child as an alternative […]
Targeting 5,000 individuals, CodeCraft, an online competition to find Sri Lanka’s most secure coder was launched in Colombo recently. The competition will be held under two categories which are for the corporate sector and the university students engaged in software development. It is held aimed at supporting Sri Lankan government’s mission to earn US $ […]
CICRA Consultancies Ltd., Sri Lanka’s pioneering information security training and consultancy provider, participated in the 2016 United States Pacific Command’s Pacific Endeavour conference for the fourth consecutive year from 22 August to 2 September in Brisbane, Australia. Nearly 250 military communication experts, non-government organisations and academic advisers from over 20 allied and partner nations were […]
Central Bank Governor Dr. Indrajit Coomaraswamy, while speaking at the Cyber Security Summit 2016, said that taking measures to eradicate looming cybercrime should be considered a national responsibility. “The cybercrime industry, which seeks these ICT-based services for vicious purposes, has already overtaken the illicit drug trade and is appearing as a prominent revenue generator. Many […]
At the Session 03 Panel from left Asia Policy Partners LLC, Hong Kong Managing Partner Michael R K Mudd, Microsoft Sri Lanka and Maldives Country Manager Brian Kealy, NDB Bank PLC Chief Operating Officer Rohan Muttiah and Moderator Daily FT Editor Nisthar Cassim Daily FT-CICRA Cyber Security Summit puts spotlight on vulnerability of banking and […]
Answering to a question from Daily FT about the progress of the Data Protection Act, ICTA’s Legal Adviser Jayantha Fernando said that the implementation of the much-talked act looks very positive with the enactment of the Right to Information Act in the Parliament. “The discussion has been going on for many years. It also weighs […]
Human resource or human capital is the greatest asset of an organisation but over the last few years, lack of skilled employees as well as complex information systems have made that greatest asset one of the greatest risks for an organisation, Prof. Mathew Warren, Deputy Director at Deakin University Centre for Cyber Security Research of […]
Daily FT-CICRA Holdings fourth annual Cyber Security Summit’s inaugural session sets the stage for sharing of new knowledge and insights The EC-Council Cyber Security Summit 2016 organised for the fourth consecutive time kick-started on Tuesday with high-profile international IT security experts from Sri Lanka and the region. The EC-Council Cyber Security Summit 2016 is co-organised […]
Chief guest Telecommunications and Digital Infrastructure Minister Harin Fernando addresses the Summit Telecommunications and Digital Infrastructure Minister Harin Fernando checks his mobile as he is led to the ceremonial opening of the Daily FT-CICRA Cyber Security Summit. CICRA Holdings CEO Boshan Dayaratne, Daily FT Editor Nisthar Cassim, Summit’s strategic partner Cisco Lead for Sri Lanka […]