Other influential international bodies, the International Organization for Standardization
(ISO) and the International Electrotechnical Commission (IEC), published ISO/IEC
17799:2005 [3]. These standards establish guidelines and general principles for initiating,
implementing, maintaining, and improving information security management in an
organization. The objectives outlined provide general guidance on the commonly accepted
goals of information security management. The standards consist of best practices of control
objectives and controls in the areas of information security management shown in Figure 3.2.
These objectives and controls are intended to be implemented to meet the requirements
identified by a risk assessment.