Saturday, August 28, 2010

Information Security Management System (ISO/IEC 27001)- 2W Questions


What is ISO/IEC 27001 (ISMS)?

 is auditable international standard which defines the requirements for an
Information Security Management System (ISMS) was established in 2005
 replaces the BS7799 requirements with the intention to provide the
foundation for third party audit, and is 'harmonized' with other management
standards, such as ISO 9001 and ISO 14001
 helps establish and maintain an effective information management system
 applies to all types of organizations
 is designed to be used for certification purposes
 lists a set of control objectives and controls
 emphasize on a continual improvement approach


Why ISO 27001 (ISMS)?


 a comprehensive approach to the management of information security in the
organization
 ensuring business continuity especially in the event of emergency
 ensuring compliance with the law and regulations
 reducing financial damage due to information theft and fraud
 assist in uphold of reputation of the organization as well as it’s brand
 provision of timely detection, reporting and management of security
incidents. Thus, minimize the impacts of security events
 better planning and investing in areas where proper management and
elimination of security threats are necessary
 competitive advantage and provide confidence to certified organizations as
the certification proves proper protection and management of information

2 comments:

  1. When the eccentricity has been rectified, then it is guaranteed that the organization is sticking very firmly with quality standards that are set by the ISO 22000. Therefore Global Manager Group is taking initiative in giving best ISO training presentation and details to individuals on large scale through online portal.

    ReplyDelete

  2. I know Laura well and she is principled, thoughtful, and extremely bright...more power to her!

    iso 27001 lead auditor certification online

    ReplyDelete