Member Area

FarmavitaR+ : Regulatory Affairs Network

Saturday
Jan 10th
Home arrow FarmavitaR+ Journal arrow Business News arrow Management Practice
Management Practice Print E-mail
Written by Sanjay J Daharwal   
Saturday, 03 March 2007
Article Index
Management Practice
Page 2
Page 3
Page 4
Page 5
Page 6
Page 7
Page 8
Page 9
Page 10
Page 11
Page 12
Page 13
Page 14
Page 15
Page 16
Page 17
The objectives outlined provide general guidance on the commonly accepted goals of information security management. ISO/IEC 17799:2005 contains best practices of control objectives and controls in the following areas of information security management:

  • security policy;
  • organization of information security;
  • asset management;
  • human resources security;
  • physical and environmental security;
  • communications and operations management;
  • access control;
  • information systems acquisition, development and maintenance;
  • information security incident management;
  • business continuity management;
  • Compliance.
Security policy: Adopting a security process that outlines an organization's expectations for security, this can then demonstrate management’s support and commitment to security.

Security organization: Having a management structure for security, including appointing security coordinators, delegating security management responsibilities and establishing a security incident response process

Business continuity management: Planning for disasters--natural and man-made--and recovering from them. Asset classification and control: Conducting a detailed assessment and inventory of an organization's information infrastructure and information assets to determine an appropriate level of security. 

Personnel security: Making security a key component of the human resources and business operations. This includes writing security expectations in job responsibilities (IT admins and end users), screening new personnel for criminal histories, using confidentiality agreements when dealing with sensitive information and having a reporting process for security incidents.

Physical and environmental security: Establishing a policy that protects the IT infrastructure, physical plant and employees. This includes controlling building access, having backup power supplies, performing routine equipment maintenance and securing off-site equipment.

“It contains 71 Pages of Security Management Goodness the main highlighting features are.”

 The control objectives and controls in ISO/IEC 17799:2005 are intended to be     implemented to meet the requirements identified by a risk assessment. ISO/IEC 17799:2005 is intended as a common basis and practical guideline for developing organizational security standards and effective security management practices, and to help build confidence in inter-organizational activities. 


Last Updated ( Thursday, 29 March 2007 )
 
< Prev   Next >
Advertisement

3D Content Cloud

BabelFish Translator




Click Flag for Translation

Sponsors

Member Log-in

Log-in to FarmavitaR+ community & network Membership is FREE!

Who's Online

Subscribe to RSS


Regulatory Affairs

RA Section

Reports

Click to Reports

Events

Click to Events

Groups

Groups