Guest
Information Security in Project Management
Example of how to implement A.6.1.5: Information Security in Project Management?
Assign topic to the user
Expert
Rhand Leal
May 04, 2017
Answer: There are many similarities with implementing an ISMS that you can use to drive the implementation of this control:
1 – You have to define information security objectives and include them in the project objectives, the same way you define information security objectives for an ISMS aligned with organization's objectives, the only difference is that these objectives are restricted to the scope of the project.
2 – You have to perform at the beginning, and periodically, information risk assessments in the project, like you would do it with other business processes, to identify necessary controls
3 – You have to ensure that information security practices are part of all phases of the project (e.g., from the issue of the project charter to project closing).
In short, you can think about the inclusion of information security in project management as if you are going to implement a small ISMS that will fit the projects needs and be proportional to the project' s lifetime and budget.
This article will provide you further explanation about Information security in project management:
- How to manage security in project management according to ISO 27001 A.6.1.5 https://advisera.com/27001academy/what-is-iso-27001/
These materials will also help you regarding Information security in project management:
- ISO 27001 Annex A Controls in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- Preparations for the ISO Implementation Project: A Plain English Guide https://advisera.com/books/preparations-for-the-iso-implementation-project-a-plain-english-guide/
Comment as guest or Sign in
May 04, 2017
May 04, 2017
May 04, 2017