Quick Links

Content on this page requires a newer version of Adobe Flash Player.

Get Adobe Flash player

   
 
  ISO 27001  
  ISO/IEC 27001:2005 Information technology -- Security techniques -- Specification for an Information Security Management System is the formal standard against which organizations may seek independent certification of their Information Security Management Systems (meaning their frameworks to design, implement, manage, maintain and enforce information security processes and controls systematically and consistently throughout the organizations).

The standard covers all types of organizations (e.g. commercial enterprises, government agencies and non-profit organizations). It specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented ISMS within the context of the organization’s overall risk management processes. It specifies requirements for the implementation of security controls customized to the needs of individual organizations or parts thereof. It does not mandate specific information security controls.

ISO/IEC 27001 “is intended to be suitable for several different types of use, including:

  • Use within organisations to formulate security requirements and objectives;
  • Use within organisations as a way to ensure that security risks are cost-effectively managed;
  • Use within organisations to ensure compliance with laws and regulations;
  • Use within an organisation as a process framework for the implementation and management of controls to ensure that the specific security objectives of an organisation are met;
  • The definition of new information security management processes;
  • Identification and clarification of existing information security management processes;
  • Use by the management of organisations to determine the status of information security management activities;
  • Use by the internal and external auditors of organisations to demonstrate the information security policies, directives and standards adopted by an organisation and determine the degree of compliance with those policies, directives and standards;
  • Use by organisations to provide relevant information about information security policies, directives, standards and procedures to trading partners and other organisations that they interact with for operational or commercial reasons;
  • Implementation of a business enabling information security; and
  • Use by organisations to provide relevant information about information security to customers.”

ProMinds Consulting provides professional consultancy services for organizations willing to establish information security standards as per the ISO 27001 standard.

 
     
   
     
     
Consulting
 
  CMMI
  ISO 27001
  ISO 20000
  ISO 9001
  TL 9000
  BS 25999
  Six Sigma
  Balance Scorecard
  HIPAA
  SAS 70
  Sarbanes Oxley (SOX)
  PCI
  Cyber Laws