Expert Advice Community

Guest

Cyber Security Policy

  Quote
Guest
Guest user Created:   Oct 28, 2017 Last commented:   Oct 28, 2017

Cyber Security Policy

I work in XXXX with one of the Financial Services Organization. We are working on improving our Information Security overall and surely enhancing policies/plan and controls too. My management is expecting Cyber Security Policy also to be written separately along with Information Security Policy. I know that Cyber Security Policy is a subset of Information Security as Information Security covers all aspects of Cyber Security too. Is it advisable to write a separate Cyber Security Policy document even though we already have Information Security Policy document available ? If yes, what are the points to be taken care in Cyber Security Policy. Please provide some guidelines on it.
0 0

Assign topic to the user

ISO 27001 INFORMATION SECURITY POLICY

Define the main rules for information security management.

ISO 27001 INFORMATION SECURITY POLICY

Define the main rules for information security management.

Expert
Rhand Leal Oct 28, 2017

Answer: To ensure a better alignment between Information security and cyber security practices it is better to consider the Cyber Security Policy as a section of your Information Security Policy. Regarding which points you should consider, a good reference is the ISO 27032 standard, which provides guidelines for cyber security. In terms of policies you should consider the following topics:
- Guidelines to be followed when you are an information providing organization and when you are an information receiving organization
- Classification and categorization of information
- Information minimization
- Limited audience
- Coordination protocol

These articles will provide you further explanation about cyber security and ISO 27001:
- What is cybersecurity and how can ISO 27001 help? https://advisera.com/27001academy/blog/2011/10/25/what-is-cybersecurity-and-how-can-iso-27001-help/
- ISO 27001 vs. ISO 27032 cybersecurity standard https://advisera.com/27001academy/blog/2015/08/25/iso-27001-vs-iso-27032-cybersecurity-standard/

These materials will also help you regarding cyber security and ISO 27001:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- 9 Steps to Cybersecurity: The Manager’s Information Security Strategy Manual https://advisera.com/books/9-steps-to-cybersecurity-managers-information-security-manual/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 28, 2017

Oct 28, 2017

Suggested Topics