You are on page 1of 2

Quelly Anne Lecerio

BSIT-3H
INFORMATION ASSURANCE AND SECURITY

1. The Data Privacy Act of 2012 (Republic Act No. 10173)

2. ISO/IEC 27001
What is ISO/IEC 27001?
The most well-known standard for information security management systems (ISMS) worldwide
is ISO/IEC 27001. It outlines the specifications an ISMS must fulfill. The ISO/IEC 27001 standard
offers guidelines for creating, implementing, maintaining, and continuously improving an
information security management system to businesses of all sizes and across all industries.
When an organization or business complies with ISO/IEC 27001, it indicates that it has
implemented a risk management system for the security of its data and that system adheres to
all of the best practices and principles outlined in this international standard.
Why is ISO/IEC 27001 important?
The escalating rate of cybercrime and the perpetual emergence of new threats can make cyber
risk management challenging, if not impossible. Organizations can become more risk-aware and
proactively detect and fix vulnerabilities with the support of ISO/IEC 27001. The information
security holistic approach—vetting of people, policy, and technology—is encouraged by ISO/IEC
27001. An information security management system that complies with this standard can be
used as an instrument for operational excellence, cyber-resilience, and risk management.

3. Function of DICT in Information Assurance and Security

You might also like