ISO 27032
ISO/IEC 27032 is an international standard that provides guidance for cybersecurity by integrating information security, network security, internet security, and the protection of critical information infrastructures (CIIP) to help organizations defend against cyber threats such as phishing and data leaks and to strengthen their digital resilience. It complements ISO 27001 by focusing on the broader digital space and providing a more comprehensive perspective on internet cybersecurity.
Main Focus
Cybersecurity: Provides high-level guidelines for improving cybersecurity.
Connecting Security Domains: Explains the relationship between information, network, internet, and cybersecurity.
Protecting Critical Infrastructure: Focuses on protecting systems essential for the functioning of society.
Practical Guidance: Helps formulate policies, implement tools, and respond to attacks (e.g., malware, phishing).
Key Features
Complement to ISO 27001: While ISO 27001 defines an Information Security Management System (ISMS), ISO 27032 provides specific guidance for cyberspace.
Target Audience Focus: Identifies stakeholders and their roles in internet security.
Updated: The 2023 version offers current guidance, including addressing newer topics such as the darknet and attack path reconstruction.