BS EN ISO
27001:2005 Information technology. Security techniques.
Information security management systems.
In conjunction with
Avitar Ltd
The aim of ISO 27001 is to provide best
practice advice in keeping personal, intellectual property,
sensitive and commercially valuable data secure; a failing that
we hear all too much about in the news, where Identity Theft is
becoming an everyday threat and data is being lost or stolen.
Published on 15 October 2005, this standard
primarily defines an Information Security Management System
(ISMS) and complements the 'code of practice', now available as
ISO 27002. The standard is not just aimed at IT departments or
companies but all organisations that involve people when
handling information that needs to be kept secure.
ISO 27001 specifies the requirements for the
information
security management system itself, against which certification
can be achieved. ISO 27001 has been harmonised to be compatible
with other management systems standards, and our consultants can
assist in integrating this as necessary.
The international status of ISO 27001 is
having a global impact and its application gathers more interest
in both information security management and certification as
organisations gain from this recognition and from increases in
security.
Our consultants can assist in designing an information security
management system (ISMS) that meets ISO 27001, APACS Standard 55
and more importantly your needs. This ensures the selection of
security controls are adequate and proportionate in protecting
your information assets and gives confidence to all interested
parties including your customers.
In today's world of Corporate Governance
this standard is suitable for different types of organisational
use, including:
Formulation of security requirements and
objectives
To ensure that security risks are cost
effectively manage
To ensure compliance with laws and
regulations
As a process framework for the
implementation and management of controls to ensure that the
specific security objectives of an organisation are met
Identification and clarification of
existing information security management processes
To determine the degree of compliance
with the policies, directives and standards adopted by an
organisation and for certification purposes
To provide relevant information about
information security policies, directives, standards and
procedures to trading partners and to customers.
Avitar are
consultants who specialise in putting in simple
uncomplicated management systems to meet the requirements of the
ISO 27001 without unnecessary administration