Articles island - a directory of quality articles, free quality articles reprint for your web site and email newsletter.
Free Articles Reprint for Your Web Site, Email Newsletter, Blog, Ezine and RSS Feed.
Submit Your Articles to Our Article Directory for Massive Exposure.
Total Live Articles: 92683  Total Categories: 389



 
  Advanced Search
Articles island Expert Author - Rohan Jagtap
Rohan Jagtap is a philosopher. He believes that our life is nothing but the result of Law of Attraction acting upon us. He says you can change your life by changing your own thoughts. He read thousands of articles from web related with LOA. And now he knows LOA gives the answer of any problem that you are facing in your life.
Home » Business » Corporate » Use ISO 17799 to Improve Security and Minimize Risks

Articles island Expert Author - nurani
Author Name:
nurani

Country:
Canada

Member Since:
2 Aug 2007

Total Live Articles:
1



Email to Friends
Rate this Article
Bookmark this Article
Print this Article
Report this Article
Leave a Comment





Use ISO 17799 to Improve Security and Minimize Risks

By: nurani
Total views: 44
Word Count: 988
Date:Aug 2nd 2007
Article Rating: No Ratings Yet

Most organizations are dependent upon their information and business systems, leaving them exposed to critical loss in the aftermath of a security breach. Fortunately, by implementing an information security management system ("ISMS"), as outlined in the only internationally accepted standard/code to address information security, a business can significantly reduce the risk of a security breach.

ISO/IEC 17799:2005 ("ISO 17799"), known as the Code of practice for information security management, was developed by an IT Security Subcommittee of the International Organization for Standardization and was published in June 2005. ISO 17799 is superior to other security standards because it is globally accepted and comprehensive. ISO 17799 has been cleverly crafted to work well across industries and geographies. Also, the International Organization for Standardization has consciously made this standard consistent with most other existing information security audit and control standards, such as those developed by the NIST (National Institute of Standards and Technology). Therefore, ISO 17799 can be the common framework that links to all other standards, regulatory requirements and corporate governance initiatives.

ISO 17799 provides practical guidelines for developing organizational security controls and effective security management practices. An ISO 17799 evaluation results in a snapshot of the company's security infrastructure, in that it provides a high-level view of how well (or how badly) a company implements information security. This standard is a great tool for companies whether establishing or improving information security within their organization.

The information security process traditionally has been based on sound best practices and guidelines, with the goals of preventing, detecting and containing security breaches, as well as restoration of the affected data to its previous state. While this cumulative wisdom of the ages is valid, it is also subject to various interpretations and implementations. ISO 17799 offers an achievable benchmark against which to build organizational information security.

Control Selection based on Risks Identified

ISO 17799 consists of 39 security controls, which can be used as a basis for a security risk assessment. The controls encompass all forms and types of information, whether they are electronic files, paper documents or various forms of communications such as email, fax and spoken conversations. The standard sets out a variety of hardware and software considerations, policies, procedures and organizational structures that protect a company's information assets from a broad range of modern security threats and vulnerabilities. How organizations shape their information security programs will depend on the unique requirements and risks they face. An organization should only deploy controls that relate to, and are in proportion to, the actual risks it faces.

Controls can also more simply be described as the countermeasures for risks. Apart from knowingly accepting risks considered acceptable, or transferring those risks (through insurance) to others, there are essentially four types of control:

1. Deterrent controls reduce the likelihood of a deliberate attack.
2. Preventative controls protect vulnerabilities and make an attack unsuccessful or reduce its impact.
3. Corrective controls reduce the effect of an attack.
4. Detective controls discover attacks and trigger preventative or corrective controls.

It is essential that any controls that are implemented are cost-effective. The cost of implementing and maintaining a control should be no greater than the identified and quantified cost of the impact of the identified threat (or threats). It is not possible to provide total security against every single risk; the trade-off involves providing effective security against most risks. No board should sign off on any ISMS proposal that seeks to remove all risk from the business - the business does, after all, exist within a risk framework and, since it is impossible to exist risk-free, there is little point in proposing to eliminate every risk.

No organization should invest in information security technology (hardware or software) or implement information security management processes and procedures without having carried out an appropriate risk and control assessment that assures them that:

- The proposed investment (the total cost of the control) is the same as, or less than, the cost of the identified impact;
- The risk classification, which takes into account its probability, is appropriate for the proposed investment; and
- Mitigating the risk is a priority - i.e. all the risks with higher prioritization have already been adequately controlled and, therefore, it is appropriate now to be investing in controlling this one.

Once information security needs and requirements are identified, a suitable set of controls from ISO 17799 can be established, implemented, monitored, reviewed and improved upon in order to ensure that the specific security objectives of the organization are met.

ISO 17799 is a comprehensive information security code of practice that provides enterprises an internationally recognized and structured methodology for information security. In addition to ISO 17799, the International Organization for Standardization also published ISO 27001, which specifies a number of requirements for establishing, implementing, maintaining and improving an ISMS using the controls outlined in ISO 17799.

ISO 27001 is the formal standard against which an organization may seek independent certification of their ISMS. While certification is entirely optional, as of January 2007, over 3000 organizations world-wide were ISO 27001 certified, demonstrating their commitment to information security. Organizations may be certified compliant with ISO 27001 by a number of accredited certification bodies worldwide. ISO 27001 certification generally involves a two stage audit process, with a "table top" review of key documentation at the first stage and a more in-depth audit of the ISMS at the second stage. The certified organization would need to be re-assessed periodically by the certification body.

In summary, organizations face threats to their information assets on a daily basis. At the same time, they are becoming increasingly dependent on these assets. Technical solutions are only one portion of a holistic approach to information security. Establishing broad information security requirements in the framework of the organization's own unique risk environment is essential.

About The Author-- Fazila Nurani is the President and Founder of PrivaTech Consulting (http://www.privatech.ca), based in Toronto, Canada. Visit Fazila Nurani's bio. Nurani advises organizations on compliance with global privacy laws and managing information security risks. She may be reached at +1.905.886.0751 or fazilanurani@rogers.com.

Article Source: Articles island - Free article submission and free reprint articles


Most Viewed Corporate Articles




Most Viewed Corporate Articles:

A Corporate Security Guide to Software Piracy
Almost from the first computer software commercially sold, software pirates have flourished. The international...

Rules Governing Articles Of Association And Company Formation
The Articles of Association of a limited liability company are an essential element of any limited company for...

Corporate Credit - Corporations Rely on Credit
Corporate credit is essential to the operation and health of small businesses across the world....

Layoffs and Bureaucracy
A while back Id been reading the stories on the last major layoff at HP, and it really struck a nerve. HP anno...

Practical Pandemic Planning Advice
Avian (Bird) Flu is a worldwide health crisis waiting to happen, yet too few companies are prepared to deal wi...

Where to Find Available Office Space
Available office space can be found in one of three ways. Each of their advantages and disadvantages are outli...

Use ISO 17799 to Improve Security and Minimize Risks
All businesses need to take key steps to protect their information assets. By implementing an information secu...

Gates and Microsoft Part i
One of the big news items in the last year was Bill Gates announcing that he was leaving Microsoft. It wasn't ...

The Rise and Fall of Novell
Once again one of the great brand names of High Tech has been prominently in the news, for disconcerting reaso...

Lean Manufacturing Process For Beginners
Every company has been asking what is lean manufacturing process. This article answers what is this manufactur...


Recent Corporate Articles




Recent Corporate Articles:

How to Easily and Quickly and Get Prospects to Call You
Doing well in business entails the customers to run after those who are the best of the best rather than the o...

Who Are Your Customers?
Are you aware of who your customers are? Are they male or female? What is their age? Are they married or si...

Keeping Customers And Shareholders Happy
A market downturn can take the luster out of a growing business and end any glory days it may have experienced...

The Benefits of Helping Non-Profit Organizations
This is kind of a no brainer, but the article tells why....

Effective Team Building Events
Are you trying to choose a team building event for your work team? This article will help guide you through th...

How To Arrange Your Company Away Day
What to do and how to arrange your company away day....

Time For Outdoor Team Building
The types of outdoor team building activities available and the factors your should consider to make sure it i...

Annual Return And Accounting Rules For A UK Dormant Company
Rules apply to dormant companies in the UK with regard to accounting documents and submission of information t...

Are Corporate Treasure Hunts Good For Morale?
A look at why corporate treasure hunts. Why they are a great way of improving motivation for your team....

Using a DMC for Special Events Planning in Baltimore
What do you do when your boss puts you in charge of planning a company event in Baltimore, and you're a lifelo...

Most Viewed Articles by nurani




Most Viewed Articles by nurani:

Use ISO 17799 to Improve Security and Minimize Risks
All businesses need to take key steps to protect their information assets. By implementing an information secu...

You have permission to publish or reprint this article in your ezine, website, blog, forum, RSS feed or print publication, free of charge. As long as you keep this article with no changes(included Article Title, Article Body, Author Name, Article Source and keep all links in this article active)and you agree to our publisher terms of service. Below are ready HTML code for this article, you can copy and paste directly into your web page.

Use ISO 17799 to Improve Security and Minimize Risks -- HTML Version:


Use ISO 17799 to Improve Security and Minimize Risks -- Summary:

Use ISO 17799 to Improve Security and Minimize Risks -- Keywords:
1   2   3 Good!   4   5   6 Very Good!!   7   8   9   10 Excellent!!!  
Comments:
No Comment Posted.

Leave Comment: Please Login to leave a comment. Not a member yet? Sign Up now.