SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Implementing ISMS for systems with different cyber security risks

  Quote
Guest
Guest user Created:   Apr 27, 2016 Last commented:   Apr 27, 2016

Implementing ISMS for systems with different cyber security risks

We need to implement ISMS for both our business office systems & operational systems. For the operational systems we have a greater risk for Cyber Security. How do we have to implement ISMS for this, and what will be the difference or main focal point for cyber security?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Apr 27, 2016

Answer:

I'm not sure if I understood your question correctly, but if you are asking how to cover the cyber security risks with ISO 27001 implementation for two different systems within the company, the answer is the following: one of the first steps in ISO 27001 implementation is to perform the risk assessment. Once you know which risks you have in those two systems, then you'll choose appropriate security controls that would fit either first or second system, or both. You'll have to list all of those controls in the Statement of Applicability, and make sure you define for which system is particular control intended for.

In other words, ISO 27001 does not prescribe upfront certain safeguards for certain systems, you have to find out the controls yourself through the analysis called risk assessment - you'll find more information here: The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

This article will also help you: ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 27, 2016

Apr 27, 2016

Suggested Topics