Expert Advice Community

Guest

ISO 27001 objective and requirements

  Quote
Guest
Guest user Created:   Nov 25, 2019 Last commented:   Nov 25, 2019

ISO 27001 objective and requirements

Pelo que li da norma o objetivo é garantir a confidencialidade, a integridade e a disponibilidade da informação. A qualidade da informação não me parece que seja preocupação da ISO 27001. A qualidade é necessária, mas, é controlada por outros meios. Quando vejo solicitação de carta de competência, por falta de diploma de um colaborador, ou obrigatoriedade de apresentação do perfil do profissionaldo colaborador não entendo o que isso tenha a haver com segurança da informação. Entendi errado?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 25, 2019

From what I read from the standard, the goal is to ensure the confidentiality, integrity, and availability of information. The quality of information does not seem to me to be a concern of ISO 27001. Quality is necessary, but it is controlled by other means. When I see a request for a letter of competence, due to lack of an employee's diploma, or obligation to present the profile of the employee's professional, I do not understand what this has to do with information security. I got it wrong?

Please note that the objective of the standard is to protect information. Ensuring its confidentiality, integrity, and availability are the means by which this objective is achieved.

Information quality is not a mandatory requirement, but organizations can define information quality as a requirement to be protected by the ISMS if it impacts its information security objectives.

Recommendation letters, or other means to evidence competence, is a requirement of the standard (clause 7.2 c)) to ensure people have the proper experience, training, or education to perform work that can impact information security performance.

These articles will provide you further explanation about these topics:
- What is ISO 27001 https://advisera.com/27001academy/what-is-iso-27001/
- How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/
- How to demonstrate resource provision in ISO 27001 https://advisera.com/27001academy/blog/2017/04/10/how-to-demonstrate-resource-provision-in-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 25, 2019

Nov 25, 2019