Expert Advice Community

Guest

ISO 27001 controls

  Quote
Guest
Guest user Created:   May 07, 2020 Last commented:   May 07, 2020

ISO 27001 controls

How to implement more effectively ISO 27001 controls.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 07, 2020

The main rules here are:

  • you need to have clear objectives for the controls
  • the controls' objectives need to support relevant business objectives
  • responsibilities must be clearly defined (usually through policies and procedures)
  • people must have the proper competencies (usually through awareness, training, and education)

With clear control objectives, you will know which resources you need, where to apply them, who needs to be involved, and when adjustments are needed, avoiding low performance and waste. However, this is only half of the way.

With clear links between control objectives and business objectives, you can easily demonstrate to top management that the information security effort is paying off.

With clear responsibilities people will know what is expected from them, focusing on activities that add value to the business, and avoiding unrelated activities.

Finally, with proper competencies, the personnel will be more engaged with information security (they will know why is important to do what they have to do and how to perform such tasks)

These articles will provide you a further explanation about security objectives:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 07, 2020

May 07, 2020