|
Identifying and managing information security risks has never been more important or challenging. Whether the issues are internal, external, or accidental, management is expected to minimize risks and be prepared to respond to critical situations effectively and decisively. How an organization identifies and manages its risk is the key to a sustainable business. Being able to demonstrating your commitment will ensure stakeholder value.
ISO 27001 (ISO 17799 / BS7799) is a comprehensive set of controls comprising internationally defined security best practices for information systems. ISO 27001 is a comprehensive Information Security Standard that affords organizations the following benefits:
- An internationally recognized framework that can enhance information security interoperability and trust with trading partners.
- A process to evaluate, implement, maintain, and manage information security.
- A mechanism to integrate information security into the organizations overall risk management strategy.
- A vehicle to document and potentially certify “due diligence”.
- An umbrella under which multiple data protection regulations may be addressed.
- A great tool to help meet Sarbanes-Oxley Act requirements
T3i’s ISO 27001 / 17799 Certification and Readiness Assessment:
Achieving ISO 27001certification is similar to a SAS 70 audit in that an independent audit must be conducted by an internationally recognized accreditation body (Registrar). As these audits are usually considered to be a pass / fail scenario, organizations should not start an audit until and unless that are confident they will pass. T3i provides consulting expertise to that end.
- Assessment: Perform a baseline assessment and GAP analysis of the delta between existing configurations, processes, policies and ISO 17799 requirements.
- Remediation: Combine our consulting and engineering expertise with emerging technologies to provide our client with a cost effective framework and implementation of an information security program that conforms to the ISO 17799 standards.
- Certification: Engage independent third-party ISO certification registrars to provide audit and issue an ISO 27001 certification of our client’s information security posture.
Back to Certification Main
|