Expert Advice Community

Guest

Information security in project management

  Quote
Guest
Guest user Created:   Mar 26, 2017 Last commented:   Mar 26, 2017

Information security in project management

I just wondered whether you have a template for control 6.1.5 (Information Security in Project Management)? I am struggling with how to write it. Kindly provide me with some indicators in the absence of a template on what to include. I am assuming that it will impact the entire project management cycle. The issue is that we have there different entry points for new projects and ten there are some rare occasions where some projects are run by branch offices without an approval from a central body. How would you recommend going about writing the control in this case?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 26, 2017

Answer: Unfortunately we do not have a template covering Information Security in Project Management, but there are many similarities with implementing an ISMS that you can use to drive the implementation of this control:

1 - You have to define information security objectives and include them in the project objectives, the same way you define information security objectives for an ISMS aligned with organization's objectives, the only difference is that these objectives are restri cted to the scope of the project.

2 - You have to perform at the beginning, and periodically, information risk assessments in the project, like you would do it with other business processes, to identify necessary controls

3 - You have to ensure that information security practices are part of all phases of the project (e.g., from the issue of the project charter to project closing).

In short, you can think the inclusion of information security in project management as if you are going to implement a small ISMS that will fit the projects needs and be proportional to the project's lifetime and budget.

Regarding your question related to different entry points for new projects, I would recommend you to define a project management policy, establishing rules for project approval and the need to include information security as part of the project activities.

This article will provide you further explanation about Information security in project management:
- How to manage security in project management according to ISO 27001 A.6.1.5 https://advisera.com/27001academy/what-is-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 26, 2017

Mar 26, 2017