Expert Advice Community

Guest

Information Security Program

  Quote
Guest
Guest user Created:   Aug 19, 2018 Last commented:   Aug 19, 2018

Information Security Program

I’m still working on my documents and start downloading your documents and templates. My primary task for now is to create an Information Security Program (ISO) for the Organization as part of the primary requirement of our Regulator to be submitted this 3rd quarter of 2018. Looking on the templates I’m not sure where I can pattern this or probably get guidance or format on how the ISP will look like. If you have same document that I can refer with, it will be a great help.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Aug 19, 2018

Answer:

An Information Security Program is a collection of the controls that an organization needs to have in place to protect information and keep information security risks at acceptable levels.

Considering that, to create a ISP you should use the templates related to Risk Management, to identify the risks and proper treatments, and use the Statement of Applicability to present the applicable controls and how they will be implemented.

You must note that this will be only part of the ISMS, and that you should consider implementing all other documents to ensure the controls you decided to implement will be monitored periodically and improved or adjusted as needed.

This material will provide you more information:
- ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
- The basics of risk assessment and treatment according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 19, 2018

Aug 19, 2018

Suggested Topics