Featured

Support for the ISO 27001 Management System

The management team of an organization is responsible for approving the set of information security policies, which will form the foundation of the management system set up according to ISO 27001. The policies should be simple and targeted, possibly referencing more detailed procedures or instructions. The purpose of the high-level policy is to express the management's vision in a concise and effective way.

These policies should be distributed and communicated to all personnel and to all relevant external parties, such as other individuals who work intermittently at the organization's premises. Lower-level policies should be made available to appropriate staff as needed, depending on their job function and associated security requirements.

Information security management policies should be subject to version control and should be part of the management system documentation designed according to ISO 27001. It should be ensured that all individuals responsible for managing information security have access to all the necessary policies.

A good policy should address at least the following topics: - a clear definition of what is meant by information security, its overall scope, and the objective to be achieved; - the reasons why information security is important to the organization; - a statement of management support for information security; - a summary of a practical framework for risk assessment, risk management, and the selection of objectives and controls; - a summary of security policies, principles, standards, and compliance requirements; - a definition of all relevant responsibilities concerning information security; - reference to supporting documentation, such as more detailed policies; - how to manage any non-conformities and exceptions.

Remember that an auditor will check that the policy is easily accessible to all employees and relevant external parties and that it is communicated to all stakeholders. The audit will also include verifying knowledge and understanding of the policy's content.

The policy can be a standalone statement or part of a broader documentation, such as an information security policy manual. The auditor will also check that there is a clearly identified person responsible for updating the policy following any changes to the system that impact the organization's information security requirements. To ensure its continued suitability, adequacy, and effectiveness, information security policies must be periodically reviewed. This should also occur when changes take place. This process should detect all modifications that affect the management system and update the document to reflect how the organization is managing its risks. Additionally, planned periodic reviews and defined review procedures are crucial to ensure that any changes not yet detected are considered. Furthermore, staff should be informed of policy changes that may affect their role.

Information security policies play an important role in creating and maintaining an information security management system. Auditors will verify that the organization has developed procedures to respond to incidents, new vulnerabilities, threats, technological changes, or any other factors that may require a policy revision.

Periodic reviews should also be scheduled to ensure that the policy remains appropriate and economically feasible to implement in relation to the protection achieved. The auditor will verify that the schedule for such reviews is appropriate for the organization's overall risk context.

Contact us, without obligation, at this number 02.58320936 or at this email address: This email address is being protected from spambots. You need JavaScript enabled to view it.. We will be happy to assist you by providing all the useful information to start the certification process for your information security management system according to the ISO 27001 standard.

Contacts

Registered Office:
Via Nazario Sauro, 4 – 20059 Vimercate (MI)
Milan Office:
Via della Resistenza, 113 - 20090 Buccinasco
La Spezia Office:
Via Paolo Emilio Taviani, 52 – 19125 La Spezia (SP)
Sitemap