Covering data from its initial creation and storage to its final sanitization and disposal. Key Technical Domains
The primary goal of ISO/IEC 27040 is to help organizations protect information while it is stored and during its transfer across storage-related communication links. Its core objectives include:
The standard breaks down storage security into several critical technical areas to ensure "defense-in-depth":
ISO/IEC 27040:2024 - Information technology — Security techniques
Highlighting risks associated with storage systems, such as data breaches, corruption, and unauthorized access.
Providing specific technical guidance that expands upon the general security controls found in ISO/IEC 27002 .