2 - ISMS and the ISO 27001 Standards Family Flashcards
Critical factors to ans ISMS
CIA
Key components for IS policy
Process / procedure
Technology
User behaviour
Project Plan - Documentation - 11 sections
- Business continuity planning
- System acquisition, development and maintenance
- IS incident management
- Communication and operations management
- Physical and environmental security
- Personal security
- System access control
- Security policies
- Security organisation
- Compliance
- Asset classification and control
Project Plan - Decision making
- Existing IT maturity levels
- Customer requirements
- Existing training programs
- Business objectives and priorities
- Adherence to internal processes
- Internal audit capability
- Existing compliance efforts and legal requirements
- The entreprise’s ability to adapt to change
- User acceptability and awarness
- Contractual obligations
PDCA meaning
Plan - do - check - act
PDCA steps
ISMS policy
scope of the ISMS
Perform a security risk assessment
Manage the identified risk
Select controls to be implemented and applied
Prepare an SOA (statement of applicability)
SOA meaning
statement of applicability
The eleven phases of Implementation
Identify Business Objectives
Obtain Management Support
Select the proper scope of implementation
Define a method of risk assessment
Prepare an inventory of information assets to protect, and rank them according to risk based on risk assessment
Manage the risks, and create a risk treatment plan
Set up policies and procedures to control risks
Allocate resources, and train the staff
Monitor the implementation of the ISMS
Prepare for the certification audit
COnduct periodic reassessment audits
The governing principle behind an ISMS is …
an organisation should design, implement and maintain a coherent set of policies, processes and systems to manage risks to its information assets
Process Approach - Phase 1
Scope, design and build
Process Approach - Phase 2
First cycle of implementation, operation, monitoring and improvement
Process Approach - Phase 3 (BAU)
Operate, monitor and improve
Define what is a BAU
When the integration of the ISMS processes and controls are complete, the ISMS becomes a BAU (Business as Usual) system
Define what is a BAU
When the integration of the ISMS processes and controls are complete, the ISMS becomes a BAU (Business as Usual) system
PDCA - plan
policy, ISMS process, procedures and objectives for risk management and improvement of IS