Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Annex A is a subset of 27001, but 27001 is focused on security.

https://www.iso.org/isoiec-27001-information-security.html

(Even so, your point is well taken. The overall 27000 series is more business continuity (DR etc) focused rather than purely security focused.)



and to be fair, Information Security is generally accepted to cover Confidentiality, Integrity, and Availability (see: CIA Triad)... so DR/BC are definitely within scope.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: