| |
ISO
27001 (Information Security Management)
ISO/IEC 27001 is the formal standard against
which organizations may seek independent certification of
their Information Security Management System (ISMS).
ISO/IEC 27001 specifies a set of requirements for the establishment,
implementation, monitoring and review, maintenance and improvement
of an ISMS, which is a management system (a framework of policies,
procedures, physical, legal and technical security controls
forming part of the organization’s overall risk management
processes) aimed at managing information security risks. It
does not mandate specific information security controls.
The standard covers all types of organizations
(e.g. commercial enterprises, government agencies and non-profit
organizations). The ISMS is described using the Plan-Do-Check-Act
(PDCA) cycle. The system of security controls is not
merely specified and implemented as a one-off activity but
continually reviewed and adjusted to take account of changes
in the security threats, vulnerabilities and impacts of information
security failures. Bringing information security under
management control is a prerequisite for sustainable, directed
and continuous improvement.
ISO/IEC 27001 is intended to be suitable for
several different types of use, including:
- Use within organisations to formulate security requirements
and objectives;
- Use within organisations as a way to ensure that security
risks are cost-effectively managed;
- Use within organisations to ensure compliance with laws
and regulations;
- Use within an organisation as a process framework for
the implementation and management of controls to ensure
that the specific security objectives of an organisation
are met;
- The definition of new information security management
processes;
- Identification and clarification of existing information
security management processes;
- Use by the management of organisations to determine the
status of information security management activities;
- Use by the internal and external auditors of organisations
to demonstrate the information security policies, directives
and standards adopted by an organisation and determine the
degree of compliance with those policies, directives and
standards;
- Use by organisations to provide relevant information about
information security policies, directives, standards and
procedures to trading partners and other organisations that
they interact with for operational or commercial reasons;
- Implementation of a business enabling information security;
and
- Use by organisations to provide relevant information about
information security to customers.
Call Jordan Business Systems today and see
how your Information Security Management System can be enhanced
to withstand even the most aggressive threats out there.
|