Showing posts with label ISO 27001. Show all posts
Showing posts with label ISO 27001. Show all posts

Wednesday, December 14, 2011

ISMS Implementation: Examing Roles & Responsibilities by Rafidah Abdul Hamid



“Security is everyone’s responsibility”.

Everyone have roles and responsibilities for maintaining security in organization.The management, technical people, employees, vendors and contractors havedifferent roles in developing and implementing an effective security process. For this article, we will look at the roles and responsibilities of management, Information Security Department and users in implementing and maintaining information security management system (ISMS) in organization.

Management's responsibilities
Management's responsibility goes beyond the basics of support. They must set the tone for the entire program. It is not enough just to bless the program. Management must own up to the program by becoming a part of the process. Management is responsible for overseeing the development, implementation, and maintenance of ISMS. This includes defining the information security objectives of the organization, allocating an amount of money to be invested in information security, and ensuring the compliancy and enforcement of implementation.

Management has specific goals for the organization, and sometimes technical people are not in the position to understand these nuances. Both groups should understand that security is not something that can be wrapped in a package and bought off the shelf. It should be a goal that both parties strive to maintain. One of the ways to bridge the divide is by setting up an Information Security Management Committee.

It is the responsibility of management to form this committee that will be responsible for reviewing changes in the business and determining how ISMS implementation should support those changes. To make this committee success, it is good to distribute the responsibilities throughout the organization depending on the institution’s size, complexity, culture, nature of operations, and other factors. The distribution of duties should ensure an appropriate segregation of duties between individuals or organizational groups. Management should also ensure integration of security controls throughout the organization by performing the following:

-Ensure the security process is governed by organizational policies and practices
that are consistently applied,
-Require that information with similar criticality and sensitivity characteristics
be protected consistently regardless of where in the organization it resides,
-Enforce compliance with the security program in a balanced and consistent manner
across the organization, and
-Coordinate information security with physical security.

Information
Security Department Responsibilities
The Information Security Department is responsible and accountable for security administration. At a minimum, they should directly manage or oversee risk assessment, development of policies, standards, and procedures, testing, and security reporting processes. Security officers should have the authority to respond to a security event by ordering emergency actions to protect the organization from an imminent loss of information or value. They should have sufficient knowledge, background, and training, as well as an organizational position, to enable them to perform their assigned tasks.

User
Responsibilities
Users should know, understand, and be held accountable for fulfilling their security responsibilities. The means of ensuring users understanding and/or recognition of their responsibilities varies. User security awareness training is one of the most common means available to achieve recognition of responsibility and computing asset worth. Some organizations require personnel to sign an agreement that includes the protection of computing assets as a condition of employment, while others sign agreements as a condition of allowing their
connection to the organizations network. One way to ensure that every current and future user knows that security is part of his job function is to make it part of each job description. Spelling out the security function or expectations within the job description demonstrates the commitment to information security, as well as emphasizes that it is part of the job. After it is made part of the job description, it becomes something that can be considered in performance evaluations.

Conclusion
Information security is the responsibility of everyone in the organization. Management support is crucial for a successful ISMS implementation. Along with its support is a responsibility to the ongoing maintenance of this program. To have a successful ISMS implementation; management, Information Security Department and users must have a good understanding of their roles and responsibilities and be willing to take actions.

Friday, December 9, 2011

ISO27001 compliance database keeps UK companies up to date with laws and regulations

Ely, England, 6 December 2011 – There are over 70 information-related laws and statutes currently in force in the UK. Organisations need to know what laws they have to comply with and how to ensure compliance. For those implementing ISO27001, there is a requirement that their ISMS takes ‘into account business and legal or regulatory requirements, and contractual security obligations’.

Since the new UK Government’s Cyber Security Strategy was published in November, there is an even greater incentive for all industries to familiarise themselves with the existing legislation and adhere to those laws relevant them. Important laws, such as the Data Protection Act (DPA), Freedom of Information Act, Privacy and Electronic Communications Regulations and many more, exist in order to protect organisations’ information assets, as well as the well-being of their customers and stakeholders. The Information Commissioner’s Office looks after their application and has the right to fine any organisation that violates these laws. The internationally recognised ISO27001, on the other hand, ensures that companies comply with this legislation.

More importantly, some experts believe, that the new Cyber Security Strategy can only be successful if organisations are required to pursue ISO27001 with a number of mandated controls, and if businesses are encouraged to invest in improving their information security.

Speaking to risk.net in November, Alan Calder, CEO of IT Governance, stated “The big thing is that, while the Government talks about needing to take the lead and have a public–­private partnership, what it really needs to be doing is making sure companies in the UK financial sector, and outside the financial sector, take information security a massive amount more seriously".

The experts at IT Governance, the single-source provider for everything related to ISO27001 and information security, have recently launched their revised ISO27001 Compliance Database and Update Service. This is the only product on the market that holds a repository of all the 71 statutes and regulations relevant to ISO27001. Updated for 2011, the ISO27001 Compliance Database includes 10 new laws and offers regular updates (depending on the subscription period) as and when new laws are published.

ISO27001 requires organisations to develop their information security management system (ISMS), taking into account ‘business and legal or regulatory requirements, and contractual security obligations’ (Clause 4.2.1 b. 2). There are five controls in ISO/IEC 27001 Annex A which impose specific requirements in terms of identifying and staying up to date with statutory and regulatory requirements.

The ISO 27001 Compliance Database and Update Service identifies the specific clauses within each legal instrument that organisations must comply with, providing best-practice guidance on how to comply with that clause. It also enables an ISMS project manager to select appropriate controls at the individual clause level

Source:
http://www.itgovernance.co.uk/media/article.aspx?news_id=1204