SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

ISO 27001: ISMS

  Quote
Guest
Guest user Created:   Jun 09, 2020 Last commented:   Jun 09, 2020

ISO 27001: ISMS

I have implemented ISO 27001 ISMS in an insurance company. Now they want to know, whether they need any other framework of Cyber Security to protect them from Cyber threats, OR, the ISO 27001 isms framework is sufficient for them?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 09, 2020

ISO 27001 provides a comprehensive approach for information security and Cyber Security, so an additional framework would be necessary only if:

  • there are legal requirements (e.g., laws, regulations, or contracts) demanding the implementation of another framework
  • there are needed controls that are not covered, or not properly covered, by controls in Annex A (e.g., NIST SP 800-53 publication also provides one family of 16 controls for the management of information security programs)

In case you do not have the above-mentioned situations, ISO 27001 is sufficient to cover cybersecurity

This article will provide you a further explanation about NIST and cybersecurity:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 09, 2020

Jun 09, 2020