Posts

Showing posts from November, 2017

Clauses in ISO 27001

Clauses in ISO 27001 Clause 4: Context of the organization ·          4.1: Understanding the Organization and its context ·          4.2: Understanding the needs and expectations of interested parties ·          4.3: Determining the scope of the information security management system ·          4.4: Information security management system Clause 5: Leadership ·          5.1: Leadership and Commitment ·          5.2: Policy ·          5.3: Organizational roles, responsibilities and authorities Clause 6: Planning ·          6.1: Actions to address risks and opportunities ·          6.2: Information security objectives and planning to achieve them Clause 7: Support ·          7.1: Resources ·          7.2: Competence ·          7.3: Awareness ·          7.4: Communication ·          7.5: Documented Information Clause 8: Operations ·          8.1: Operational Planning and control ·          8.2: Information security risk assessment ·         

What is ISO 27001?

ISO 27001 is a standard which helps organizations manage information security. It was published by International Standardization Organization (ISO). The latest revised version is ISO 27001:2013. First version was published in 2005. This standard was developed on British Standards BS 7799-2. Which type of organizations can get certified for ISO 27001? ISO 27001 can be implemented in any kind of organization, profit or non-profit, private or state-owned, small or large. ISO 27001 establishes framework for the implementation of information security management in an organization. Organizations can also get certified for ISO 27001. The independent certification bodies perform the audit and upon compliance with the standard, it issues the certificate to organizations. What are the benefits of ISO 27001?             New client acquisition and retention of old clients            Avoid losses and penalties for data breaches           Comply with business, legal and reg