ISO17799信息安全休系(1)

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

1ISO17799INFORMATIONSECURITY!!#$%&'!#$%&Ifyourinformation’snotsafe,yourfuture’snotsecure2InformationSecurityNomatterhowsecureandwellprotectedanorganisationappearstobe,sensitiveinformationcanbeleakedwithoutyouevenrealisinguntilit’stoolate.Allinformationinalldepartments,whetheroncomputerdisk,paperorintheheadsofthoseyouemploy,isatriskfromanynumberofveryrealthreats.InformationsecurityisnolongerjustanissueforITmanagers–asinglebreachofinformationsecuritycouldcostyourcompanyhardearnedprofitswhilstdoingirreparabledamagetoyourimageandreputation.Yourcapacitytotradeprofitablydependsonyourabilitytomanagethisriskeffectively.Asthenumberofreportedinformationsecuritybreachesconsistentlyincreases,theneedtocreateamanagementframeworkforinformationsecurityintensifies.AnInformationSecurityManagementSystem(ISMS)–ISO17799,theInternationalStandardsOrganisation’sversionofBS7799,willprovideawell-provenframeworktoinitiate,implement,maintainandmanageinformationsecuritywithinanyorganisation.ISO17799OnceyoustartusingISO17799asabasisforyourISMS,yourmanagementsystemcanbeauditedandregisteredbyathirdparty.Thisprocessaddssignificantvaluetotheongoingeffectivenessofthesystem.ByimplementingandregisteringtotheaccreditedBS7799schemeyouwillbewellonthewaytobeingregisteredtoISO17799whenaregistrationprocessispublished.Atthatpoint,BSIwillworkwithyoutoensureasmoothtransitionfromBS7799totheISO17799certificationstandard.IFYOUAREN’TMANAGINGRISKS,YOUSHOULDBETheissueofinformationsecurityseesorganisationsofallsizesandfromallsectors,withanidenticalproblem–theirinherentvulnerability.3!#$%&'()*+,-./'(01+23!#$%&'()*+,-./0123#$4!!#$%&'()*+,-./012%345!#$%&'()*+,-./0123456fq!#==!#$%&'()!#$%&'()*+,-./%0123!#$%&'()*+,-./0123456!#$%&!#$%&'()*+,-.-/01234!#$%&'()*+,-./0!1fpjpfpl=NTTVV==!#$%&_pTTVV!#$%&'()*+,-+./012!#$%fpl=NTTVV!#$!#$%&'#!(!#$%&'()*+,-!#$%&'()*!#$%&$'()*+_p=TTVV!fplNTTVV!#$%&'($!#$%&'()*_pf!#$_p=TTVV!fpl=NTTVV!#$%&'()*+,-.%/!#$%&'()!#$%&'()*+,!#$%&'==!#$%!4FEATURESANDBENEFITSOFISO17799DuetotheallencompassingnatureofISO17799,wehavehighlightedthekeyareasyouwouldhavetoaddresswhenusingtheISO17799InformationSecurityManagementSystem:Securitypolicy–AdocumenttodemonstratemanagementsupportandcommitmenttotheInformationSecurityManagementSystemprocess.Securityorganisation–Anestablishedmanagementframeworktoinitiateandcontroltheimplementationofinformationsecuritywithinyourorganisationandtomanageongoinginformationsecurityprovision.Assetclassificationandcontrol–Acomprehensiveinventoryofassetswithresponsibilityassignedtoensurethateffectivesecurityprotectionismaintained.Personnelsecurity–Welldefinedjobdescriptionsforallstaffoutliningsecurityrolesandresponsibilities.Physicalandenvironmentalsecurity–Aclearandconcisedefinitionofthesecurityrequirementsforyourpremisesandthepeoplewithinthem.Communicationsandoperationsmanagement–OptimiseyourcommunicationtofacilitatesmoothoperationoftheInformationSecurityManagementSystem.Accesscontrol–Networkmanagementtoensurethatonlythosewiththeappropriateresponsibilityhaveaccesstoinformationinthenetworksandtheprotectionofthesupportinginfrastructure.Systemsdevelopmentandmaintenance–EnsuringthatITprojectsandsupportactivitiesareconductedinasecuremannerthroughdatacontrolandencryptionwherenecessary.Businesscontinuitymanagement–Amanagedprocessfordevelopingandmaintainingbusinesscontingencyplanswhichprotectcriticalbusinessprocessesfrommajordisastersorfailures.Compliance–Ademonstrationtoclients,employeesandtheauthoritiesofyourcommitmenttomeetstatutoryorregulatoryinformationsecurityrequirements.Ifthisexercisehashighlightedareasthatneedmorework,oryouhaveanyqueriesregardingtheissuesraised,pleasecontactBSI.5fpl=NTTVV!#fpl=NTTVV!#$%&'()*+,!-.)/012!#$%&'()*+,-./012345678!!==!#$%&'()*+,-./!==!#$%&'()*+,-./012#$!#$%&'()*+,-./0!#$==!#$%&'()*+,-./!==!#$%&'()*+,-.!#$==!#$%&'()*+,-./01!#$==!#$%&'()*+,-./01!#$%&'()!==!#$%&'()*+,-./01234!#$%&'!()*+,-./!#$==!fq!#$%&'()!#$%&'()*+,-.!#$%==!#$%&'()*+,-./!#$%&'()*+,-.!==!#$%&'()*+,-.!#$%&'()*+,-./0123$I_pf6ADDEDVALUETHROUGHINTEGRATIONWhiletheBritishandInternationalManagementSystemstandardsareautonomous,theyaremorecompatiblethaneverbefore.Integratingyoursystemsgiveslimitlesspotentialwhileaddingvalueandefficiencytoyourorganisation.Integratedmanagementsystemsarefastbecomingaprerequisitetotradeglobally,securepartnershipsandmaintaincustomerloyalty.Theyaredesignedtohelpyourorganisationworkasacompleteunitwithacommonobjective,whilepromotingdevelopmentinabalancedandholisticway.OurIntegratedAssessmentService(IAS)isdesignedtohelporganisationsreachregistrationtoanumberofmanagementsystemstandardscost-effectivelywithminimaldisruptiontoworkactivity.So,shouldyouwanttodemonstrateyourcommitmenttotheenvironment(ISO14001),health&safety(OHSAS18001)orquality(ISO9001:2000)alongsideinformationsecurity(ISO17799)tocreateatotalmanagementsolution,wec

1 / 12
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功