SlideShare ist ein Scribd-Unternehmen logo
1 von 12
iFour ConsultancyISO 27001 – A8 Asset Management
 Anything that has value to the organization
Asset
ISO for Software application development India
Assets
Software &
Hardware
Infrastructure
Information
People
Risk
assessment
‱ Key element of identifying risks, together with threats and
vulnerabilities.
Responsibility
Assignment
‱ Defines asset owners
‱ Assigns owners the responsibility to protect the
confidentiality, integrity and availability of the information
Why are assets important for information security management?
ISO for Software application development India
 A set of business processes designed to manage the lifecycle and inventory of
technology assets
 It provides:
 Lowers IT costs,
 Reduces IT risk and
 Improves productivity
Asset Management
A8 Asset Management Clauses
ISO for Software application development India
‱ Responsibility for assets8.1
‱ Information Classification8.2
‱ Media Handling8.3
 To identify organizational assets and define appropriate protection responsibility
8.1.1 Inventory of Assets
8.1.2 Ownership of assets
8.1.3 Acceptable use of assets
8.1.4 Return of Assets
8.1 Responsibility for assets
ISO for Software application development India
Controls for Responsibility for assets
‱ Assets associated with information and information processing facilities shall
be identified and an inventory of these assets shall be drawn up and
maintained
Inventory of Assets
‱ Assets maintained in the inventory shall be ownedOwnership of assets
‱ Rules for acceptable use of information and of assets associated with
information and information processing facilities shall be identified,
documented and implemented
Acceptable use of
assets
‱ All employees and external party users shall return all of the organizational
assets in their possession upon termination of their employment, contract or
agreement
Return of Assets
 To ensure that information receives an appropriate level of protection in
accordance with its importance to the organization
8.2.1 Classification of information
8.2.2 Labelling of information
8.2.3 Handling of assets
8.2 Information Classification
ISO for Software application development India
Controls for Information Classification
ISO for Software application development India
‱ Information shall be classified in terms of legal requirements,
value, criticality and sensitivity to unauthorised disclosure or
modification
Classification of
information
‱ An appropriate set of procedures for information labelling shall
be developed and implemented in accordance with information
classification scheme adopted by the organization
Labelling of
information
‱ Procedures for handling assets shall be developed and
implemented in accordance with the information classification
scheme adopted by the organization
Handling of assets
References
http://advisera.com/27001academy/knowledgebase/how-to-handle-asset-
register-asset-inventory-according-to-iso-27001/
https://en.wikipedia.org/wiki/ISO/IEC_27001:2013
ISO for Software application development India
Visit- http://www.ifour-consultancy.com
Or
http://www.ifourtechnolab.com
For more details
ISO for Software application development India
ISO for Software application development India

Weitere Àhnliche Inhalte

Andere mochten auch (8)

Iso 9001:2015 Documented Information Guidance
Iso 9001:2015 Documented Information GuidanceIso 9001:2015 Documented Information Guidance
Iso 9001:2015 Documented Information Guidance
 
Access Control Presentation
Access Control PresentationAccess Control Presentation
Access Control Presentation
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Ű„ÙŠŰČو 9001/2015 ŰšŰ§Ù„Ù„ŰșŰ© Ű§Ù„ŰčŰ±ŰšÙŠŰ©
Ű„ÙŠŰČو 9001/2015 ŰšŰ§Ù„Ù„ŰșŰ© Ű§Ù„ŰčŰ±ŰšÙŠŰ©Ű„ÙŠŰČو 9001/2015 ŰšŰ§Ù„Ù„ŰșŰ© Ű§Ù„ŰčŰ±ŰšÙŠŰ©
Ű„ÙŠŰČو 9001/2015 ŰšŰ§Ù„Ù„ŰșŰ© Ű§Ù„ŰčŰ±ŰšÙŠŰ©
 
Information Security Management System ISO/IEC 27001:2005
Information Security Management System ISO/IEC 27001:2005Information Security Management System ISO/IEC 27001:2005
Information Security Management System ISO/IEC 27001:2005
 
Cryptography.ppt
Cryptography.pptCryptography.ppt
Cryptography.ppt
 
Risk management
Risk managementRisk management
Risk management
 
INFORMATION SECURITY
INFORMATION SECURITYINFORMATION SECURITY
INFORMATION SECURITY
 

KĂŒrzlich hochgeladen

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

KĂŒrzlich hochgeladen (20)

A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 

ISO 27001 A8 Asset Management

  • 1. iFour ConsultancyISO 27001 – A8 Asset Management
  • 2.  Anything that has value to the organization Asset ISO for Software application development India Assets Software & Hardware Infrastructure Information People
  • 3. Risk assessment ‱ Key element of identifying risks, together with threats and vulnerabilities. Responsibility Assignment ‱ Defines asset owners ‱ Assigns owners the responsibility to protect the confidentiality, integrity and availability of the information Why are assets important for information security management? ISO for Software application development India
  • 4.  A set of business processes designed to manage the lifecycle and inventory of technology assets  It provides:  Lowers IT costs,  Reduces IT risk and  Improves productivity Asset Management
  • 5. A8 Asset Management Clauses ISO for Software application development India ‱ Responsibility for assets8.1 ‱ Information Classification8.2 ‱ Media Handling8.3
  • 6.  To identify organizational assets and define appropriate protection responsibility 8.1.1 Inventory of Assets 8.1.2 Ownership of assets 8.1.3 Acceptable use of assets 8.1.4 Return of Assets 8.1 Responsibility for assets ISO for Software application development India
  • 7. Controls for Responsibility for assets ‱ Assets associated with information and information processing facilities shall be identified and an inventory of these assets shall be drawn up and maintained Inventory of Assets ‱ Assets maintained in the inventory shall be ownedOwnership of assets ‱ Rules for acceptable use of information and of assets associated with information and information processing facilities shall be identified, documented and implemented Acceptable use of assets ‱ All employees and external party users shall return all of the organizational assets in their possession upon termination of their employment, contract or agreement Return of Assets
  • 8.  To ensure that information receives an appropriate level of protection in accordance with its importance to the organization 8.2.1 Classification of information 8.2.2 Labelling of information 8.2.3 Handling of assets 8.2 Information Classification ISO for Software application development India
  • 9. Controls for Information Classification ISO for Software application development India ‱ Information shall be classified in terms of legal requirements, value, criticality and sensitivity to unauthorised disclosure or modification Classification of information ‱ An appropriate set of procedures for information labelling shall be developed and implemented in accordance with information classification scheme adopted by the organization Labelling of information ‱ Procedures for handling assets shall be developed and implemented in accordance with the information classification scheme adopted by the organization Handling of assets
  • 11. Visit- http://www.ifour-consultancy.com Or http://www.ifourtechnolab.com For more details ISO for Software application development India
  • 12. ISO for Software application development India

Hinweis der Redaktion

  1. ISO for Software application development India - http://www.ifour-consultancy.com/
  2. ISO for Software application development India - http://www.ifour-consultancy.com/
  3. ISO for Software application development India - http://www.ifour-consultancy.com/
  4. ISO for Software application development India - http://www.ifour-consultancy.com/
  5. ISO for Software application development India - http://www.ifour-consultancy.com/
  6. ISO for Software application development India - http://www.ifour-consultancy.com/
  7. ISO for Software application development India - http://www.ifour-consultancy.com/
  8. ISO for Software application development India - http://www.ifour-consultancy.com/
  9. ISO for Software application development India - http://www.ifour-consultancy.com/