|
Download PDF
The Information Security management standard ISO 17799 (built upon and encapsulating BS 7799) is rapidly becoming the primary information security standard for e-commerce activity worldwide. With its increased adoption the pressure for trading partners to follow each other's lead becomes intense.
The focus of the standard is the building of an appropriate information security management infrastructure or "Information Security Management System" (ISMS). An ISMS consists of several layered subordinate systems. Each layer addresses a different category of information risk to which the organisation is exposed.
In the wider context, information security management is the key component of an organisation's Information Management programme and is significant in its own right. The ISMS is usually built over an extended period of time and consists of several projects.
Usually the first of these projects is the review the current information security infrastructure and the development of a suitable Information Security Policy, Strategy and programme Development Plan.
In business terms an Information Security Management programme often has a relatively high Return on Investment, especially for the initial projects addressed and even for the first programme set-up project.
Information Security Policy and Strategy Formation
Establishing or upgrading an Information Security Policy and Strategy is best done in an initial set-up or review project.
MWR InfoSecurity provide a consultant who will facilitate the identification, analysis and implementation of a workable information security policy and strategy Our experience at Board level means we can effectively communicate the relationship between strategic business needs and immediate IT and information security issues.
Policy development is demanding, requiring the co-ordination of various departments and the collation of several categories of information and knowledge. Our consultants act as mentors during the process to ensure that each stage is managed properly. They provide advice and assistance to ensure that you get the very best value from their involvement.
Our consultancy is finite, with agreed milestones.
We produce effective results based on tried and tested methods.
|