This article needs additional citations for verification. IEC 27000-series standards are descended from a corporate security standard donated by Shell to a UK as nzs iso 31000 2009 pdf initiative in the early 1990s . Within each chapter, information security controls and their objectives are specified and outlined.

The information security controls are generally regarded as best practice means of achieving those objectives. For each of the controls, implementation guidance is provided. Each organization is expected to undertake a structured information security risk assessment process to determine its specific requirements before selecting controls that are appropriate to its particular circumstances. It is practically impossible to list all conceivable controls in a general purpose standard. Note: this is merely an illustration.

Other than in public areas such as the reception foyer, and private areas such as rest rooms, visitors should be escorted at all times by an employee while on the premises.