ISO/IEC 27011
Go home

Copyright © 2010 IsecT Ltd.

 

 

Sponsor this page!

 

Contact us to advertise here.

 

ISO/IEC 27011:2008  Information technology -- Security techniques -- Information security management guidelines for telecommunications organizations based on ISO/IEC 27002

 

This ISMS implementation guide for the telecomms industry has been developed jointly by ITU-T and ISO/IEC JTC1/SC27. It is published jointly as ITU-T X.1051 and ISO/IEC 27011. 

 

ITU-T Recommendation X.1051 Information security management system – Requirements for telecommunications (ISMS-T) was originally published in English in July 2004, followed by Spanish, French and Russian translations in 2005.  It is based on the ISMS standards extant at that time i.e.:

  • ITU-T Recommendation X.800 (1991), Security architecture for Open Systems Interconnection for CCITT applications.
  • ITU-T Recommendation X.805 (2003), Security architecture for systems providing end-to-end communications.
  • ISO 9001:2000, Quality management systems – Requirements.
  • ISO 14001:1996, Environmental management systems – Specification with guidance for use.
  • ISO/IEC 17799:2000, Information technology – Code of practice for information security management (now known as ISO/IEC 27002).
  • ISO/IEC Guide 73:2002, Risk management – Vocabulary – Guidelines for use in standards.
  • BS 7799-2:2002, Information Security Management Systems – Specification with Guidance for use (now known as ISO/IEC 27001).

 

The summary states:

    “For telecommunications organizations, information and the supporting processes, telecommunications facilities, networks and lines are important business assets. In order for telecommunications organizations to appropriately manage these business assets and to correctly and successfully continue their business activities, information security management is extremely necessary. This Recommendation provides the requirements on information security management for telecommunications organizations.

    This Recommendation specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented information security management system (ISMS) within the context of the telecommunication's overall business risks. It specifies requirements for the implementation of security controls customized to the needs of individual telecommunications or parts thereof.”