ISO 27001 Management of information security
What is ISO 27001?ISO 27001 is a specification for the management of information security. It is applicable to all sectors of industry and not confined to just information held on computers. Information may be printed or written on paper, stored electronically, transmitted by post or email, shown on films, or spoken in conversation.
According to its documentation, ISO 27001 uses a topdown, risk-based approach and is technology-neutral. The specification defines a six-part planning process: as given : 1). Define a security policy. 2). Define the scope of the ISMS. 3). Conduct a risk assessment. 4). Manage identified risks. 5). Select control objectives and controls to be implemented. 6).Prepare a statement of applicability.
Benefits to your company of ISO 27001 certification
- Demonstration of credibility and trust
- Proven business credentials
- Establishes that laws and regulations are being met
- Openings in new markets
- Ensures commitment to on-going information security
- Customer satisfaction
- Provides confidence to stakeholders, customer, trading partners, employees