ISO 27001 Policies - PowerPoint PPT Presentation

About This Presentation
Title:

ISO 27001 Policies

Description:

ISO 27001 Policies for more info- – PowerPoint PPT presentation

Number of Views:57
Slides: 4
Provided by: Username withheld or not provided

less

Transcript and Presenter's Notes

Title: ISO 27001 Policies


1
Indicative List of Policies to be framed for ISO
270012013
2
  • Organization should define information security
    related policies which is approved by management
    and sets the organizations approach to managing
    its information security objectives.
  • a) Business Strategy, b) contracts, regulations
    and legislations and c) security threat
    environment are the source of requirements which
    information security policies should address.
  • What should Information Security Policy cover?
  • Definition of Information security, objectives
    and principles to direct all activities related
    to information security
  • Assignment of responsibilities of Information
    Security management to defined roles
  • Processes of handling non-conformities and
    exceptions

3
Indicative List of policies
  • Information Security
  • Access control
  • Information classification and handling
  • Physical and environmental security
  • Acceptable use of assets
  • Clear Desk and clear screen
  • Information Transfer
  • Mobile device and teleworking
  • Restriction on software installations and use
  • Back-up
  • Protection from malware
  • Management of technical vulnerabilities
  • Cryptographic controls
  • Communication security
  • Privacy and protection of personally identifiable
    information
  • Supplier relationships
  • These policies should be communicated to relevant
    internal and stakeholders in the context of
    awareness of information security.
Write a Comment
User Comments (0)
About PowerShow.com