ISO 27001 Transition Management
- Adoption of ISO 27001 is accelerating internationally.
- Organisations are recognising that from being a discriminator it will soon be a prerequisite to conducting business in many sectors.
- Alignment with the ISO 27001 standard can be a daunting task.
- commissum's experienced professionals are able to manage the transition process for you efficiently.
The benefits of commissum managing the process for you include:
- Knowledge of the standard and the implementation process.
- Limited disruption to the business.
- Management controls established in empathy with the values of the business.
- Certification "right first time" for lower cost.
ISO 27001 Management Transition Issues
Establishing the Information Security Management System (ISMS) necessary to achieve alignment with the ISO 27001 standard can be a daunting task. If done in-house, it is likely to divert significant resources and attention from the tactical demands of security management and administration, and from the business of the organisation in general. If you have decided to seek formal certification, you will wish to adopt a "right first time" approach, as failing to achieve it will not only reflect badly on your business and security management practices, but may also also significantly increase the cost of the process.
The UK Department of Trade and Industry (DTI) has published a roadmap for achieving alignment with ISO 27001. The process is complex, and for efficient and effective implementation it requires experience and knowledge of risk management, and the establishment of security controls and documentation.
Approach
The UK DTI guidance material stresses that an organisation should use risk management techniques to establish the scope and depth of requirement for security controls. Controls and processes must be appropriate to the business. commissum's experienced professionals are able to manage the process for you efficiently, the elements of the approach being:
- Proven management plans used to conduct assignment.
- ISO 27001 gap analysis undertaken to establish requirements.
- Experienced IT Security Manager conducts requirement review and analysis.
- Definition of control objectives and statement of applicability maps the organisation's security requirements to teh applicable clauses of the standard.
- Implementation plan drawn up to achieve control objectives.
- Management of implementation process.
- Audits conducted to test readiness for independent third-party review by an accredited organisation, leading to formal certification.
ISO 27001 Transition Management Customer Benefits:
Clients benefit from the applied knowledge of experienced commissum professionals:
- Knowledge of the standard and its implementation process.
- Limited disruption to the business from day-to-day management of the process.
- Security management and administration controls established in empathy with the values of the business.
- Faster and more assured certification (or self-certification) - "right first time" for a lower cost.
- Assistance in selecting and co-ordinating with an appropriate certification agency.
Get in touch with one of our security consultants today
- No obligation
- Expert advice
- Tailored solutions
"From the start the project went very smoothly despite the short notice. commissum maintained excellent communication throughout ........ their flexibility and responsiveness right up to the end of the project was of great value to us.”
Mr Keith H, Senior Business Manager - UK Local Government
Latest News
Leading USA military contractor QinetiQ hacked and ransacked by Chinese hackers for three years
A new report from Bloomberg, the business information provider (www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html) outlines how hackers from China stealthily infiltrated the computer systems of QinetiQ North America, a leading espionage and military contractor to the US government, and the US branch of the British defence technology company QinetiQ. A vast range of highly ...Wed 08 May, 2013 //
Suspected hacker arrested after “biggest-ever DDoS attack”
Police in Spain have arrested a Dutch national on suspicion of launching the largest-ever “Distributed Denial of Service” (DDoS) attack. Sven Olaf Kamphuis, 35, was arrested on April 25th near Barcelona, Spain. At the time, he was in possession of a specially-equipped van set up as a mobile computing and ...Tue 30 Apr, 2013 //
Hackers break into large cloud provider, claim to have credit card details
Some days ago, hackers gained access to computers owned by Linode, a company providing cloud services in the form of virtual Linux servers. The hackers gained access by using a “zero-day vulnerability” (a previously unsuspected security weakness) in Adobe ColdFusion, the software used in running the Linode web server. It ...Fri 26 Apr, 2013 //


