Expert Advice Community

Guest

Conditions for ISO 27001 implementation

  Quote
Guest
Guest user Created:   Mar 29, 2019 Last commented:   Mar 29, 2019

Conditions for ISO 27001 implementation

We are thinking about getting certify with ISO 27001 for our company. We do NOT have active directory in place right now. Can we go ahead for the certification. or Domain will decrease our load to implement the control.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 29, 2019

Answer:

First is important to note that depending on your business scenario and information security objectives, an Active directory may not be required for certification. If you want to go for certification you have to fulfill the mandatory requirements of the standard, which can be implemented through these general steps:
- Obtain top management support
- Define and document a scope based on the needs and expectations of interested parties relevant to information security
- Define, document and communicate an information security policy
- Define roles and responsibilities relevant to operation and management of information security
- Define a risk assessment and treatment methodology
- Define and allocate competencies and resources for the operation and management of information security
- Implement risk assessment an d risk treatment (at this point you may or may not identify the Active directory as needed for your ISMS)
- Operate the security controls and generate the necessary records
- Measure, monitor and evaluate the information security performance
- Implement corrections and improvements

These articles will provide you further explanation about implementing ISO 27001:
- What is ISO 27001 https://advisera.com/27001academy/what-is-iso-27001/
- ISO 27001 implementation checklist https://advisera.com/27001academy/knowledgebase/iso-27001-implementation-checklist/
- The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

These materials will also help you regarding implementing ISO 27001:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 29, 2019

Mar 29, 2019

Suggested Topics