Information Security Management Systems

A standard that defines requirements for an information security management system that ensures the protection of confidentiality, integrity and availability of information through risk management and the implementation of appropriate controls.