|
Abstract: . . . iso 17799 Page 1 Understanding ISO 17799 Understanding ISO 17799 Chief Security Officers, LLC 14362 N. Frank Lloyd Wright Blvd. Suite 1000 Scottsdale, AZ 85260 888.237.3899 www.chiefsecurityofficers.com Page 2 2 Topics Topics Motivation Motivation Key concepts Key concepts Business case Business case Overview of ISO 17799 and BS 7799 Overview of ISO 17799 and BS 7799 - - 2 2 ISMS implementation ISMS implementation Certification process Certification process Certification outlook Certification outlook Resources Resources Page 3 3 Motivation Motivation Are you confident that your requirements, designs, code, busines Are you confident that your requirements, designs, code, busines s plans, s plans, competitor intelligence, etc. is adequately protected? competitor intelligence, etc. is . . . . . . – Interview ISMS owners and users Interview ISMS owners and users – – Review high, medium, low risk areas Review high, medium, low risk areas – – Examine security objectives and implementation Examine security objectives and implementation – – Examine records from security and management reviews Examine records from security and management reviews – – Look for linkages between core documents within the ISMS Look for linkages between core documents within the ISMS – – Report findings, give recommendation Report findings, give recommendation Page 22 22 How we help our clients How we help our clients We teach information security courses We teach information security courses – – ISO 17799 : Implementing Information Security Management Systems ISO 17799 : Implementing Information Security Management Systems – – BS 7799 BS 7799 - - 2: Auditing Information Security Management Systems 2: Auditing Information Security Management Systems Support evaluation of candidate certification bodies Support evaluation of candidate certification bodies Help develop required analysis and documentation Help develop required analysis and documentation Assess compliance using gap analysis between “ideal Assess compliance using gap analysis between “ideal model” and current implementation model” and current implementation Plan for and review remedial actions Plan for and review remedial actions Conduct shadow certification audits Conduct shadow certification audits . . . --3000,2,750,2410,20339
|