SlideShare ist ein Scribd-Unternehmen logo
1 von 11
ISO 27001
Agenda
 What is ISO 27001
 The PDCA Model
 Steps to achieve ISO
27001Certification
PDCA Model
 The "Plan-Do-Check-Act" (PDCA) model applies at different levels throughout the ISMS (cycles within cycles)
 The diagram illustrates how an ISMS takes as input the information security requirements and expectations and through the PDCA cycle
produces managed information security outcomes that satisfy those requirements and expectations
Plan
Do
Check
Act
Information security requirements
and expectations
Managed information security
PDCA Model
 Plan (establish the ISMS)
 Establish ISMS policy, objectives, processes and procedures relevant to managing risk and improving information security to deliver results in
accordance with an organization’s overall policies and objectives
 Do (implement and operate the ISMS)
 Implement and operate the ISMS policy, controls, processes and procedures
 Check (monitor and review the ISMS)
 Assess and, where applicable, measure process performance against ISMS policy, objectives and practical experience and report the results to
management for review
 Act (maintain and improve the ISMS)
 Take corrective and preventive actions, based on the results of the internal ISMS audit and management review or other relevant information, to
achieve continual improvement of the ISMS
10 Steps to Achieve ISO 27001
Step 1: Decision
 Senior management need to be behind the decision for ISO 27001 certification. There is definite value in communicating this internally,
it enforces the company’s aspiration to pursue best practice
 What is needed? Concise and positive briefing to senior management outlining benefits and how it provides a platform for business
growth
Step 2: ISO Management Representative
 The company appoints a responsible and knowledgeable manager to run the program and implementation. This person will become the
company’s ISO 27001 specialist, understanding the controls and milestones needed towards accreditation
 What is needed? Selection of the right individual with a specific job description and knowledge of ISO and ISMS requirements
10 Steps to Achieve ISO 27001
Step 3: Gap Analysis and Risk Assessment
 An assessment of risk or a gap analysis is conducted to find out what can go wrong and which threats endanger the Confidentiality, Integrity
and Availability of information. This is to understand the maturity of existing controls within the business and to determine the risk profile
 What is needed? The gap analysis followed by a risk assessment of all in scope people, processes and technology performed by a qualified
auditor. Understanding the maturity of controls and risk profile
Step 4: Scope & Implementation Plan
 The review of output from the gap analysis allows the business to validate the scope of implementation and the functional / operational
boundaries. For each risk identified, appropriate controls are set to manage the risk in a systematic way. This will ensure nothing important is
missed. Important milestones, time requirements, dates for any pre assessment and staged audits are set
 What is needed? A step by step concise guide to explain the ISO 27001 process in sufficient detail
10 Steps to Achieve ISO 27001
Step 5: Employee Introduction
 It is important to engage with employees from the beginning to ensure they buy in to the ISO 27001 certification process and respond
appropriately. Also to help them to understand the individual, company and client benefits
 What is needed? A short and easy-to-understand ISO 27001 and security introduction briefing that focuses on how employees are affected
and their role in the successful implementation
Step 6: Documentation, documentation, documentation!
 ISO 27001 certification requires extensive documentation addressing all relevant millstones and individual controls. This forms the criteria the
company is measured against to meet the ISO standard
 What is needed? A set of policies, standards and procedures to ensure the business is adhering to all requirements in an efficient and
achievable manner
10 Steps to Achieve ISO 27001
Step 7: Realisation
 With the gap analysis, scope and documentation ready, it is time to put new processes into ‘business as usual’ throughout the company to start
realising the many benefits of ISO 27001. At this stage it would be beneficial to conduct a pre assessment to ensure the company is on the right
track and validate the evidence
 What is needed? Pre assessments forms, checklists and the gathering of evidence. Communication to staff about the revised processes, the
need to adopt them fully and report back on what isn’t working
Step 8: Internal ISO 27001 Audits
 ISO 27001 requires an internal audit to assess where the company is at with the milestones and the implementation phase. An auditor will
complete documentation assessing the risk, noting controls and remediation to highlight the improvements required
 What is needed? An experienced internal or external auditor. Audit tools that include forms, complete audit checklists and audit reports
10 Steps to Achieve ISO 27001
Step 9: ISO 27001 Certification
 The most important step is to pass the ISO 27001 certification audit. An independent assessor will issue a certificate stating that the
business is meeting the ISO 27001 controls and requirements. The appointed internal representative needs to be confident with the
process they have followed and consider how to best interact with the assessor
 What is needed? Employee preparation for the ISO 27001 certification including questions that may be asked and the areas the audit will
focus on. An independent assessor from a reputable company
Step 10: Maintaining the ISO 27001 Certification
 It is important to keep the ISO management system working by its integration into daily operations. The business should focus on continual
improvement
 What is needed? A reinforcement message to employees. Focus on maintaining the standards through an internal champion. Treat it as
integral component of the business processes and not a one off project
Question & Answer
Damco iso   27001

Weitere ähnliche Inhalte

Was ist angesagt?

Iso27001 Isaca Seminar (23 May 08)
Iso27001  Isaca Seminar (23 May 08)Iso27001  Isaca Seminar (23 May 08)
Iso27001 Isaca Seminar (23 May 08)
samsontamwaiho
 
Reporting about Overview Summery of ISO-27000 Se.(ISMS)
Reporting about Overview Summery  of ISO-27000 Se.(ISMS)Reporting about Overview Summery  of ISO-27000 Se.(ISMS)
Reporting about Overview Summery of ISO-27000 Se.(ISMS)
AHM Pervej Kabir
 
ISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedureISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedure
Uppala Anand
 

Was ist angesagt? (20)

ISO 27001 Training | ISO 27001 Implementation
ISO 27001 Training | ISO 27001 ImplementationISO 27001 Training | ISO 27001 Implementation
ISO 27001 Training | ISO 27001 Implementation
 
ISO 27001 control A17 (Continuity on Information Security), and ISO 22301: co...
ISO 27001 control A17 (Continuity on Information Security), and ISO 22301: co...ISO 27001 control A17 (Continuity on Information Security), and ISO 22301: co...
ISO 27001 control A17 (Continuity on Information Security), and ISO 22301: co...
 
27001 awareness Training
27001 awareness Training27001 awareness Training
27001 awareness Training
 
NQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation Guide
 
Iso 27001 10_apr_2006
Iso 27001 10_apr_2006Iso 27001 10_apr_2006
Iso 27001 10_apr_2006
 
NQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA Your Risk Assurance Partner
NQA Your Risk Assurance Partner
 
Why ISO27001 For My Organisation
Why ISO27001 For My OrganisationWhy ISO27001 For My Organisation
Why ISO27001 For My Organisation
 
Iso27001 Isaca Seminar (23 May 08)
Iso27001  Isaca Seminar (23 May 08)Iso27001  Isaca Seminar (23 May 08)
Iso27001 Isaca Seminar (23 May 08)
 
Iso 27000 it management systems presentation peter greenham iigi fwr group i...
Iso 27000 it management systems  presentation peter greenham iigi fwr group i...Iso 27000 it management systems  presentation peter greenham iigi fwr group i...
Iso 27000 it management systems presentation peter greenham iigi fwr group i...
 
All you wanted to know about iso 27000
All you wanted to know about iso 27000All you wanted to know about iso 27000
All you wanted to know about iso 27000
 
Reporting about Overview Summery of ISO-27000 Se.(ISMS)
Reporting about Overview Summery  of ISO-27000 Se.(ISMS)Reporting about Overview Summery  of ISO-27000 Se.(ISMS)
Reporting about Overview Summery of ISO-27000 Se.(ISMS)
 
ISO 27001 Certification - The Benefits and Challenges
ISO 27001 Certification - The Benefits and ChallengesISO 27001 Certification - The Benefits and Challenges
ISO 27001 Certification - The Benefits and Challenges
 
Overview of ISO 27001 ISMS
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMS
 
6 steps how to get iso 27000 certification?
6 steps how to get iso 27000 certification?6 steps how to get iso 27000 certification?
6 steps how to get iso 27000 certification?
 
What is ISO 27001 ISMS
What is ISO 27001 ISMSWhat is ISO 27001 ISMS
What is ISO 27001 ISMS
 
Iso 27001 2013
Iso 27001 2013Iso 27001 2013
Iso 27001 2013
 
NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001
 
ISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedureISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedure
 
Iso 27001 isms presentation
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentation
 
ISO 27001 - three years of lessons learned
ISO 27001 - three years of lessons learnedISO 27001 - three years of lessons learned
ISO 27001 - three years of lessons learned
 

Andere mochten auch (7)

nirbhay-1
nirbhay-1nirbhay-1
nirbhay-1
 
World Radio Day, All year long ...
World Radio Day, All year long ...World Radio Day, All year long ...
World Radio Day, All year long ...
 
NOVEDAD DE CORRECCIÓN DE DATOS DE UBICACIÓN Y DATOS DE CONTACTO...
NOVEDAD DE CORRECCIÓN DE DATOS DE UBICACIÓN Y DATOS DE CONTACTO...NOVEDAD DE CORRECCIÓN DE DATOS DE UBICACIÓN Y DATOS DE CONTACTO...
NOVEDAD DE CORRECCIÓN DE DATOS DE UBICACIÓN Y DATOS DE CONTACTO...
 
Ahmad Hassan 2015 media CV
Ahmad Hassan 2015 media  CVAhmad Hassan 2015 media  CV
Ahmad Hassan 2015 media CV
 
50 Tons de Segurança no Trabalho
50 Tons de Segurança no Trabalho50 Tons de Segurança no Trabalho
50 Tons de Segurança no Trabalho
 
O Paraíso de Lúcifer
O Paraíso de LúciferO Paraíso de Lúcifer
O Paraíso de Lúcifer
 
Los comienzos de la edad media (1)
Los comienzos de la edad media (1)Los comienzos de la edad media (1)
Los comienzos de la edad media (1)
 

Ähnlich wie Damco iso 27001

Ähnlich wie Damco iso 27001 (20)

Damco iso 27001
Damco iso   27001Damco iso   27001
Damco iso 27001
 
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptxISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
 
Get iso 27000 certification in 7 steps
Get iso 27000 certification in 7 stepsGet iso 27000 certification in 7 steps
Get iso 27000 certification in 7 steps
 
Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001
 
ISO 27001 Certification - VA.pdf
ISO 27001 Certification - VA.pdfISO 27001 Certification - VA.pdf
ISO 27001 Certification - VA.pdf
 
ISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdfISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdf
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
What is ISO 45001 certification (OH&SMS) requirements for organizations?
What is ISO 45001 certification (OH&SMS) requirements for organizations?What is ISO 45001 certification (OH&SMS) requirements for organizations?
What is ISO 45001 certification (OH&SMS) requirements for organizations?
 
ISO 9001 Certification India
ISO 9001 Certification IndiaISO 9001 Certification India
ISO 9001 Certification India
 
ISO 9000 & ISO 14000: pptx..............
ISO 9000 & ISO 14000: pptx..............ISO 9000 & ISO 14000: pptx..............
ISO 9000 & ISO 14000: pptx..............
 
formation iso 27001.pptx
formation iso 27001.pptxformation iso 27001.pptx
formation iso 27001.pptx
 
What are the steps for ISO 9001 Certification
What are the steps for ISO 9001 CertificationWhat are the steps for ISO 9001 Certification
What are the steps for ISO 9001 Certification
 
Qsys Profile
Qsys ProfileQsys Profile
Qsys Profile
 
Iso9000
Iso9000Iso9000
Iso9000
 
ISO Implementation Roadmap- By Motaharul Islam
ISO Implementation Roadmap- By Motaharul IslamISO Implementation Roadmap- By Motaharul Islam
ISO Implementation Roadmap- By Motaharul Islam
 
Intro to ISO
Intro to ISOIntro to ISO
Intro to ISO
 
Iso27001 Audit Services
Iso27001 Audit ServicesIso27001 Audit Services
Iso27001 Audit Services
 
What are the steps for ISO 50001 Certification
What are the steps for ISO 50001 CertificationWhat are the steps for ISO 50001 Certification
What are the steps for ISO 50001 Certification
 
Internal audit day 1
Internal audit day 1Internal audit day 1
Internal audit day 1
 
ISO 9000.pptx
ISO 9000.pptxISO 9000.pptx
ISO 9000.pptx
 

Mehr von Dipin Sharma (7)

2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
Curriculum outline
Curriculum outlineCurriculum outline
Curriculum outline
 
Cucumber outline
Cucumber outlineCucumber outline
Cucumber outline
 
Damco iso 27001
Damco iso   27001Damco iso   27001
Damco iso 27001
 

Kürzlich hochgeladen

Call Now ≽ 9953056974 ≼🔝 Call Girls In Shankar vihar ≼🔝 Delhi door step delev...
Call Now ≽ 9953056974 ≼🔝 Call Girls In Shankar vihar ≼🔝 Delhi door step delev...Call Now ≽ 9953056974 ≼🔝 Call Girls In Shankar vihar ≼🔝 Delhi door step delev...
Call Now ≽ 9953056974 ≼🔝 Call Girls In Shankar vihar ≼🔝 Delhi door step delev...
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Greenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptxGreenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptx
zohiiimughal286
 
一比一原版(UdeM学位证书)蒙特利尔大学毕业证学历认证怎样办
一比一原版(UdeM学位证书)蒙特利尔大学毕业证学历认证怎样办一比一原版(UdeM学位证书)蒙特利尔大学毕业证学历认证怎样办
一比一原版(UdeM学位证书)蒙特利尔大学毕业证学历认证怎样办
ezgenuh
 
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Saket 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
shivangimorya083
 
Call Girls In Kotla Mubarakpur Delhi ❤️8448577510 ⊹Best Escorts Service In 24...
Call Girls In Kotla Mubarakpur Delhi ❤️8448577510 ⊹Best Escorts Service In 24...Call Girls In Kotla Mubarakpur Delhi ❤️8448577510 ⊹Best Escorts Service In 24...
Call Girls In Kotla Mubarakpur Delhi ❤️8448577510 ⊹Best Escorts Service In 24...
lizamodels9
 
Business Bay Escorts $#$ O56521286O $#$ Escort Service In Business Bay Dubai
Business Bay Escorts $#$ O56521286O $#$ Escort Service In Business Bay DubaiBusiness Bay Escorts $#$ O56521286O $#$ Escort Service In Business Bay Dubai
Business Bay Escorts $#$ O56521286O $#$ Escort Service In Business Bay Dubai
AroojKhan71
 
9990611130 Find & Book Russian Call Girls In Vijay Nagar
9990611130 Find & Book Russian Call Girls In Vijay Nagar9990611130 Find & Book Russian Call Girls In Vijay Nagar
9990611130 Find & Book Russian Call Girls In Vijay Nagar
GenuineGirls
 
一比一原版(PU学位证书)普渡大学毕业证学历认证加急办理
一比一原版(PU学位证书)普渡大学毕业证学历认证加急办理一比一原版(PU学位证书)普渡大学毕业证学历认证加急办理
一比一原版(PU学位证书)普渡大学毕业证学历认证加急办理
ezgenuh
 
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdfSales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Aggregage
 
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
dollysharma2066
 

Kürzlich hochgeladen (20)

John Deere 335 375 385 435 Service Repair Manual
John Deere 335 375 385 435 Service Repair ManualJohn Deere 335 375 385 435 Service Repair Manual
John Deere 335 375 385 435 Service Repair Manual
 
Call Now ≽ 9953056974 ≼🔝 Call Girls In Shankar vihar ≼🔝 Delhi door step delev...
Call Now ≽ 9953056974 ≼🔝 Call Girls In Shankar vihar ≼🔝 Delhi door step delev...Call Now ≽ 9953056974 ≼🔝 Call Girls In Shankar vihar ≼🔝 Delhi door step delev...
Call Now ≽ 9953056974 ≼🔝 Call Girls In Shankar vihar ≼🔝 Delhi door step delev...
 
(INDIRA) Call Girl Surat Call Now 8250077686 Surat Escorts 24x7
(INDIRA) Call Girl Surat Call Now 8250077686 Surat Escorts 24x7(INDIRA) Call Girl Surat Call Now 8250077686 Surat Escorts 24x7
(INDIRA) Call Girl Surat Call Now 8250077686 Surat Escorts 24x7
 
John deere 425 445 455 Maitenance Manual
John deere 425 445 455 Maitenance ManualJohn deere 425 445 455 Maitenance Manual
John deere 425 445 455 Maitenance Manual
 
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...
 
How To Troubleshoot Mercedes Blind Spot Assist Inoperative Error
How To Troubleshoot Mercedes Blind Spot Assist Inoperative ErrorHow To Troubleshoot Mercedes Blind Spot Assist Inoperative Error
How To Troubleshoot Mercedes Blind Spot Assist Inoperative Error
 
ENJOY Call Girls In Okhla Vihar Delhi Call 9654467111
ENJOY Call Girls In Okhla Vihar Delhi Call 9654467111ENJOY Call Girls In Okhla Vihar Delhi Call 9654467111
ENJOY Call Girls In Okhla Vihar Delhi Call 9654467111
 
Greenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptxGreenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptx
 
一比一原版(UdeM学位证书)蒙特利尔大学毕业证学历认证怎样办
一比一原版(UdeM学位证书)蒙特利尔大学毕业证学历认证怎样办一比一原版(UdeM学位证书)蒙特利尔大学毕业证学历认证怎样办
一比一原版(UdeM学位证书)蒙特利尔大学毕业证学历认证怎样办
 
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Saket 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
 
Stay Cool and Compliant: Know Your Window Tint Laws Before You Tint
Stay Cool and Compliant: Know Your Window Tint Laws Before You TintStay Cool and Compliant: Know Your Window Tint Laws Before You Tint
Stay Cool and Compliant: Know Your Window Tint Laws Before You Tint
 
design a four cylinder internal combustion engine
design a four cylinder internal combustion enginedesign a four cylinder internal combustion engine
design a four cylinder internal combustion engine
 
Call Girls In Kotla Mubarakpur Delhi ❤️8448577510 ⊹Best Escorts Service In 24...
Call Girls In Kotla Mubarakpur Delhi ❤️8448577510 ⊹Best Escorts Service In 24...Call Girls In Kotla Mubarakpur Delhi ❤️8448577510 ⊹Best Escorts Service In 24...
Call Girls In Kotla Mubarakpur Delhi ❤️8448577510 ⊹Best Escorts Service In 24...
 
Business Bay Escorts $#$ O56521286O $#$ Escort Service In Business Bay Dubai
Business Bay Escorts $#$ O56521286O $#$ Escort Service In Business Bay DubaiBusiness Bay Escorts $#$ O56521286O $#$ Escort Service In Business Bay Dubai
Business Bay Escorts $#$ O56521286O $#$ Escort Service In Business Bay Dubai
 
9990611130 Find & Book Russian Call Girls In Vijay Nagar
9990611130 Find & Book Russian Call Girls In Vijay Nagar9990611130 Find & Book Russian Call Girls In Vijay Nagar
9990611130 Find & Book Russian Call Girls In Vijay Nagar
 
John Deere Tractors 6130M 6140M Diagnostic Manual
John Deere Tractors  6130M 6140M Diagnostic ManualJohn Deere Tractors  6130M 6140M Diagnostic Manual
John Deere Tractors 6130M 6140M Diagnostic Manual
 
一比一原版(PU学位证书)普渡大学毕业证学历认证加急办理
一比一原版(PU学位证书)普渡大学毕业证学历认证加急办理一比一原版(PU学位证书)普渡大学毕业证学历认证加急办理
一比一原版(PU学位证书)普渡大学毕业证学历认证加急办理
 
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdfSales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
 
Call me @ 9892124323 Call Girl in Andheri East With Free Home Delivery
Call me @ 9892124323 Call Girl in Andheri East With Free Home DeliveryCall me @ 9892124323 Call Girl in Andheri East With Free Home Delivery
Call me @ 9892124323 Call Girl in Andheri East With Free Home Delivery
 
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
 

Damco iso 27001

  • 2. Agenda  What is ISO 27001  The PDCA Model  Steps to achieve ISO 27001Certification
  • 3. PDCA Model  The "Plan-Do-Check-Act" (PDCA) model applies at different levels throughout the ISMS (cycles within cycles)  The diagram illustrates how an ISMS takes as input the information security requirements and expectations and through the PDCA cycle produces managed information security outcomes that satisfy those requirements and expectations Plan Do Check Act Information security requirements and expectations Managed information security
  • 4. PDCA Model  Plan (establish the ISMS)  Establish ISMS policy, objectives, processes and procedures relevant to managing risk and improving information security to deliver results in accordance with an organization’s overall policies and objectives  Do (implement and operate the ISMS)  Implement and operate the ISMS policy, controls, processes and procedures  Check (monitor and review the ISMS)  Assess and, where applicable, measure process performance against ISMS policy, objectives and practical experience and report the results to management for review  Act (maintain and improve the ISMS)  Take corrective and preventive actions, based on the results of the internal ISMS audit and management review or other relevant information, to achieve continual improvement of the ISMS
  • 5. 10 Steps to Achieve ISO 27001 Step 1: Decision  Senior management need to be behind the decision for ISO 27001 certification. There is definite value in communicating this internally, it enforces the company’s aspiration to pursue best practice  What is needed? Concise and positive briefing to senior management outlining benefits and how it provides a platform for business growth Step 2: ISO Management Representative  The company appoints a responsible and knowledgeable manager to run the program and implementation. This person will become the company’s ISO 27001 specialist, understanding the controls and milestones needed towards accreditation  What is needed? Selection of the right individual with a specific job description and knowledge of ISO and ISMS requirements
  • 6. 10 Steps to Achieve ISO 27001 Step 3: Gap Analysis and Risk Assessment  An assessment of risk or a gap analysis is conducted to find out what can go wrong and which threats endanger the Confidentiality, Integrity and Availability of information. This is to understand the maturity of existing controls within the business and to determine the risk profile  What is needed? The gap analysis followed by a risk assessment of all in scope people, processes and technology performed by a qualified auditor. Understanding the maturity of controls and risk profile Step 4: Scope & Implementation Plan  The review of output from the gap analysis allows the business to validate the scope of implementation and the functional / operational boundaries. For each risk identified, appropriate controls are set to manage the risk in a systematic way. This will ensure nothing important is missed. Important milestones, time requirements, dates for any pre assessment and staged audits are set  What is needed? A step by step concise guide to explain the ISO 27001 process in sufficient detail
  • 7. 10 Steps to Achieve ISO 27001 Step 5: Employee Introduction  It is important to engage with employees from the beginning to ensure they buy in to the ISO 27001 certification process and respond appropriately. Also to help them to understand the individual, company and client benefits  What is needed? A short and easy-to-understand ISO 27001 and security introduction briefing that focuses on how employees are affected and their role in the successful implementation Step 6: Documentation, documentation, documentation!  ISO 27001 certification requires extensive documentation addressing all relevant millstones and individual controls. This forms the criteria the company is measured against to meet the ISO standard  What is needed? A set of policies, standards and procedures to ensure the business is adhering to all requirements in an efficient and achievable manner
  • 8. 10 Steps to Achieve ISO 27001 Step 7: Realisation  With the gap analysis, scope and documentation ready, it is time to put new processes into ‘business as usual’ throughout the company to start realising the many benefits of ISO 27001. At this stage it would be beneficial to conduct a pre assessment to ensure the company is on the right track and validate the evidence  What is needed? Pre assessments forms, checklists and the gathering of evidence. Communication to staff about the revised processes, the need to adopt them fully and report back on what isn’t working Step 8: Internal ISO 27001 Audits  ISO 27001 requires an internal audit to assess where the company is at with the milestones and the implementation phase. An auditor will complete documentation assessing the risk, noting controls and remediation to highlight the improvements required  What is needed? An experienced internal or external auditor. Audit tools that include forms, complete audit checklists and audit reports
  • 9. 10 Steps to Achieve ISO 27001 Step 9: ISO 27001 Certification  The most important step is to pass the ISO 27001 certification audit. An independent assessor will issue a certificate stating that the business is meeting the ISO 27001 controls and requirements. The appointed internal representative needs to be confident with the process they have followed and consider how to best interact with the assessor  What is needed? Employee preparation for the ISO 27001 certification including questions that may be asked and the areas the audit will focus on. An independent assessor from a reputable company Step 10: Maintaining the ISO 27001 Certification  It is important to keep the ISO management system working by its integration into daily operations. The business should focus on continual improvement  What is needed? A reinforcement message to employees. Focus on maintaining the standards through an internal champion. Treat it as integral component of the business processes and not a one off project