After considering different standards we chose ISO 27001 [10]
for the following reasons: The ISO 27002 standard is the actual
guideline on best-practice in information security management.
However, as with best practice frameworks in the related field
of IT governance, individual controls can be ignored in an
attempt to customize the guideline to the actual organizational
needs – and in fact this is the common case [13]. By choosing
the certification standard ISO 27001 instead,