<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.securityprocedure.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>ISO27001</title>
 <link>http://www.securityprocedure.com/tag/iso27001</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>12 Important Steps in ISO 27001 implementation and certification</title>
 <link>http://www.securityprocedure.com/12-important-steps-iso-27001-implementation-and-certification</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img220.imageshack.us/img220/1995/iso27kismsimplementatioct2.jpg&quot;&gt;&lt;/p&gt;
&lt;p&gt;A simple tips and steps for the smooth implementation and certification of ISMS IS 27001&lt;/p&gt;
&lt;p&gt;&lt;b&gt;1. Get Management Support&lt;/b&gt;&lt;br /&gt;
The first thing that you should do is get a management support. ISO 27001 implementation need a corporate wide top down approach. Make sure that you have approval and support from higher management level&lt;/p&gt;
&lt;p&gt;&lt;b&gt;2. Define ISMS Scope&lt;/b&gt;&lt;br /&gt;
Whether integrated for all information security layers or just partial for data center, server or infrastructure is basically depends on your need and capability. Most of companies find some difficulties when implementing this standard for entire department. So be selective when defining the scope and limitation&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3. Inventory Information Assets&lt;/b&gt;&lt;br /&gt;
Inventory asset is the next important thing. Make sure that all of assets recorded properly. Make sure that intellectual and shared asset is also not missed. Collecting this information assets usually facing a challenge since many of information is distributed and separated in several functions.&lt;/p&gt;
&lt;p&gt;4. Conduct Information Security Risk Assessment&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/12-important-steps-iso-27001-implementation-and-certification&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/12-important-steps-iso-27001-implementation-and-certification#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/iso27001">ISO27001</category>
 <category domain="http://www.securityprocedure.com/tag/tips">Tips</category>
 <enclosure url="http://www.securityprocedure.com/files/ISO27k ISMS implementation and certification process.gif" length="63882" type="image/gif" />
 <pubDate>Tue, 25 Nov 2008 15:56:26 -0600</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">281 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>ISO 27001 Information Security Standard Mind Map</title>
 <link>http://www.securityprocedure.com/iso-27001-information-security-standard-mind-map</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img224.imageshack.us/img224/8133/minmapmu0.png&quot;&gt;&lt;br /&gt;
Confuse about ISO 27001/17799 implementation? below ISO 27001 mind map that help you gain understanding with the latest Information System Security Standard&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.2shared.com/file/4189263/9554ee88/ISO27kmindmap.html&quot;&gt;Download&lt;/a&gt;&lt;/p&gt;
</description>
 <comments>http://www.securityprocedure.com/iso-27001-information-security-standard-mind-map#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/iso-standard">ISO Standard</category>
 <category domain="http://www.securityprocedure.com/tag/iso27001">ISO27001</category>
 <pubDate>Thu, 30 Oct 2008 16:10:43 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">276 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>ISO 27001 information Security Management System Checklist</title>
 <link>http://www.securityprocedure.com/iso-27001-information-security-management-system-checklist</link>
 <description>&lt;p&gt;Information Security Policy&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Whether there exists an Information security policy, which is approved by the management, published and communicated as appropriate to all employees.&lt;/li&gt;
&lt;li&gt;Whether the policy states management commitment and sets out the organizational approach to managing information security.&lt;/li&gt;
&lt;li&gt;Whether the Information Security Policy is reviewed at planned intervals, or if significant changes occur to ensure its continuing suitability, adequacy and effectiveness.&lt;/li&gt;
&lt;li&gt;Whether the Information Security policy has an owner, who has approved management responsibility for development, review and evaluation of the security policy.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Internal Organization&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/iso-27001-information-security-management-system-checklist&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/iso-27001-information-security-management-system-checklist#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/audit">Audit</category>
 <category domain="http://www.securityprocedure.com/tag/iso-standard">ISO Standard</category>
 <category domain="http://www.securityprocedure.com/tag/iso27001">ISO27001</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <pubDate>Tue, 15 Apr 2008 03:58:12 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">115 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Comparison between COBIT, ITIL and ISO 27001</title>
 <link>http://www.securityprocedure.com/comparison-between-cobit-itil-and-iso-27001</link>
 <description>&lt;div style=&#039;float:right; margin-left:10px;&#039;&gt;
&lt;script src=&quot;http://digg.com/tools/diggthis.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;&lt;/div&gt;
&lt;p&gt;Many friend of mine keep asking me about what is should be implemented first to improve their information system management: whether taking Cobit, ITIL, or ISO27001. And the next question usually which one is the easiest to be implemented in their company.
&lt;p&gt;To be able to answer this question, let me tell you the definition of this three major standard in information system, who has a little bit difference in basic concept.
&lt;p&gt;&lt;B&gt;COBIT&lt;/B&gt;&lt;br&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityprocedure.com/control-objectives-information-and-related-technology-cobit&quot;&gt;Cobit&lt;/a&gt; is stand for Control Objective over Information and Related Technology. Cobit issued by ISACA (Information System Control Standard) a non profit organization for IT Governance. The Cobit main function is to help the company, mapping their IT process to ISACA best practices standard. Cobit usually choosen by the company who performing information system audit, whether related to financial audit or general IT audit.
&lt;p&gt;&lt;B&gt;ITIL&lt;/B&gt;&lt;br&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.securityprocedure.com/information-technology-infrastructure-library&quot;&gt;ITIL&lt;/a&gt; is stand for Information Technology Library. ITIL issued by OGC, is a set of framework for managing IT Service Level. Although ITIL is quite similar with COBIT in many ways, but the basic difference is Cobit set the standard by seeing the process based and risk, and in the other hand ITIL set the standard from basic IT service.
&lt;p&gt;&lt;B&gt;ISO27001&lt;/B&gt;&lt;br&gt;&lt;br /&gt;
&lt;a href=&#039;&#039;http://www.securityprocedure.com/isoiec-27001&quot;&gt;ISO27001&lt;/a&gt; is much more different between COBIT and ITIL, because ISO27001 is a security standard, so it has smaller but deeper domain compare to COBIT and ITIL.&lt;br /&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/comparison-between-cobit-itil-and-iso-27001&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/comparison-between-cobit-itil-and-iso-27001#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/cobit">COBIT</category>
 <category domain="http://www.securityprocedure.com/tag/iso27001">ISO27001</category>
 <category domain="http://www.securityprocedure.com/tag/itil">ITIL</category>
 <category domain="http://www.securityprocedure.com/tag/standard">Standard</category>
 <pubDate>Mon, 25 Feb 2008 19:34:06 -0600</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">22 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>ISO/IEC 27001</title>
 <link>http://www.securityprocedure.com/isoiec-27001</link>
 <description>&lt;p&gt;ISO/IEC 27001 part of a growing family of ISO/IEC standards, the &#039;ISO/IEC 27000 series&#039; is an information security management system (ISMS) standard published in October 2005 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Its full name is ISO/IEC 27001:2005 - Information technology -- Security techniques -- Information security management systems -- Requirements but it is commonly known as &quot;ISO 27001&quot;.&lt;/p&gt;
&lt;p&gt;It is intended to be used in conjunction with ISO/IEC 27002, the Code of Practice for Information Security Management, which lists security control objectives and recommends a range of specific security controls. Organizations that implement an ISMS in accordance with the best practice advice in ISO/IEC 27002 are likely simultaneously to meet the requirements of ISO/IEC 27001 but certification is entirely optional (unless mandated by the organization&#039;s stakeholders).&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/isoiec-27001&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/isoiec-27001#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/iso27001">ISO27001</category>
 <category domain="http://www.securityprocedure.com/tag/standard">Standard</category>
 <pubDate>Thu, 21 Feb 2008 21:54:11 -0600</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">8 at http://www.securityprocedure.com</guid>
</item>
</channel>
</rss>
