SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Security levels to have in the company

  Quote
Guest
Guest user Created:   Jun 30, 2020 Last commented:   Jun 30, 2020

Security levels to have in the company

What are the security levels to have in the company, type initial, medium, advanced? We are implementing information security in the company, and I need to know and understand how the security levels work and what do I need to have to reach each level? Can you help me with information?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 30, 2020

First, it is important to note that ISO 27001 does not prescribe levels of security, only that the information is adequately protected.

In this context, what generally occurs is the definition of information classification levels (eg public, restricted, and confidential), which require an increasing order of resources as the classification of information increases. The specific resources to be used will depend on the outcome of the risk assessment and applicable legal requirements.

For more information, see:

As you mentioned initial, medium and advanced levels, I understand that it is also worth mentioning process maturity, which is also not required by the standard, but which can help in the implementation of the information security management system.

For more information, see:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 30, 2020

Jun 30, 2020

Suggested Topics