BS EN ISO 27001:2005
Information technology. Security techniques. Information
security management systems.
In conjunction with
Avitar Ltd
The aim of ISO 27001 is to provide best practice advice in
keeping personal, intellectual property, sensitive and
commercially valuable data secure; a failing that we hear
all too much about in the news, where Identity Theft is becoming
an everyday threat and data is being lost or stolen.
Published on 15 October 2005, this standard primarily defines an
Information Security Management System (ISMS) and complements
the 'code of practice', now available as ISO 27002. The standard
is not just aimed at IT departments or companies but all
organisations that involve people when handling information that
needs to be kept secure.
ISO 27001 specifies the requirements for the information
security management system itself, against which certification
can be achieved. ISO 27001 has been harmonised to be compatible
with other management systems standards, and our consultants can
assist in integrating this as necessary.
The international status of ISO 27001 is having a global impact
and its application gathers more interest in both information
security management and certification as organisations gain from
this recognition and from increases in security.
Our consultants can assist in designing an information security
management system (ISMS) that meets ISO 27001, APACS Standard 55
and more importantly your needs. This ensures the selection of
security controls are adequate and proportionate in protecting
your information assets and gives confidence to all interested
parties including your customers.
In today's world of Corporate Governance this standard is
suitable for different types of organisational use, including:
Formulation of security requirements and objectives
To ensure that security risks are cost effectively manage
To ensure compliance with laws and regulations
As a process framework for the implementation and management
of controls to ensure that the specific security objectives
of an organisation are met
Identification and clarification of existing information
security management processes
To determine the degree of compliance with the policies,
directives and standards adopted by an organisation and for
certification purposes
To provide relevant
information about information security policies, directives,
standards and procedures to trading partners and to
customers.
Avitar are consultants who specialise in putting in simple
uncomplicated management systems to meet the requirements of the
ISO 27001 without unnecessary administration