Strengthening data protection and information security: How ISO/IEC 27701, 27001 and 27002 work together
Today, many organizations are faced with the challenge of no longer viewing information security and data protection as separate disciplines, but rather as closely interlinked elements of a uniform management system. While information security primarily regulates technical and organizational protective measures for systems, data and processes, data protection places additional demands on transparency, legal bases, data subject rights and the responsible handling of personal information. These two perspectives are becoming increasingly intertwined and form the basis for a holistic level of security and data protection. The ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27701 standards provide a coherent, internationally recognized foundation for this.








