Protect you computer and your data


ftxonline.com keyword stats



Most current MSN search phrases:

file extension lnk  

Become Confident in Your ISO 27001 Practices

Managers who claim that their organizationsbusiness requirement. UK cheque printers, for
comply with ISO/IEC 27001:2005 but that theyinstance, are required to comply with a
see no need to go through the bureaucracy ofsectoral version of ISO27001 and suppliers to
getting the 'badge on the wall' are onlythe NHS are expected to be on track for
deceiving themselves. The reality, I suspect,certification (there is now a health sector
is that the vast majority of organizationsversion of ISO17799) - even if the NHS itself
that won't submit their Information Securitystill has some way to go. Business Process
Management Systems (ISMS) to an externalOutsourcing companies are finding it much
audit against "> ISO 27001 fear that, when itsimpler to provide a copy of their ISO 27001
comes to the push, their systems would failcertificate in their tender documentation
the  test.than to answer detailed information security
questionnaires. Some of this might be
Survey after survey tells a depressinglyexpected: BS7799 was, after all, a British
familiar information insecurity story. MostStandard, and the UK government's Cabinet
recently, the 10th annual CSI/FBI surveyOffice has, for several years now, driven
revealed that, amongst thetake-up across the UK public sector. And as
security-conscious, information securitymore and more local authorities and
control-focused members of the CSI, computerpublic-sector organizations become certified,
crime continued to have a significantso the pressure for their private-sector
financial impact. The average incident lastsuppliers to achieve the standard will
year cost $204,000, and the top two securityincrease - and today's early adopters are
breaches were through virus attacks andclearly stealing a march on their
unauthorized access - both of which arecompetitors.
comprehensively controlled through the
controls and management systems mandated byAchieve  Your  Certificate  in  ISO  27001
ISO  27001.
Internationalised as "> ISO 27001,
ISO27001  Effectively  Manages  Data Securityinformation security certification can also
be a short cut to best-practice compliance
This evidence, combined with the findings ofwith a wide range of data compliance and
a recent survey carried out amongst UK-basedregulatory requirements, ranging from Data
organizations that ISO27001, suggests -Protection Acts across the EU, privacy and
somewhat contradictorily - that securingbreach legislation across the OECD, and
information is rarely the primary driver forspecific legislation such as GLBA, HIPAA and
achieving certification. The top reason wasSarbanes Oxley. Determined outsourced
commercial advantage, summed up by onesuppliers are increasingly insisting that
respondent who said that a certificate 'givestheir certificate be taken into account when
customers confidence that our data securitypreparing for and costing their annual SAS 70
is well managed and certified by anaudit, with consequently substantial
independent  source.'reductions in both the cost of, and
disruption  caused  by,  the  audit.
And it's that certification 'by an
independent source' which is the real benefitAre organizations beginning to recognize
of pursuing ISO 27001 in the first place. USthat, in fact, it is the badge on the wall
regulators implicitly recognized thethat counts? Yes, as evidenced by the
importance of external validation forincreasing number of badges. It took about
information security effectiveness when theyseven years (to December 1994) for the first
observed that: 'the best way to strengthen US1,000 certificates to be achieved, but less
information security is to treat it as athan two and half years later there are more
corporate governance issue that requires thethan 3,500 successes. And certification has a
attention  of  boards  and  CEOs.'ripple effect: every organization that
achieves ISO 27001 will expect its key
Achieve High Security Standards through ISOsuppliers to meet the standard. And this
27001means that anyone who thinks the badge
doesn't count will have nowhere to hide when
There are sectors in which the 'badge on thethe CEO comes asking why your competitors
wall' debate is already history, and in whichhave stolen your lunch.
certification is now becoming a basic



1 A B C 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 96 97 98 99 100 101 102 103 104 105