21FeatUre managed and protected and the same time meeting expectations of stakeholders partners interested parties suppliers industry laws and regulations and related requirements Achieving ISO IEC 27001 compliance can give organisations and businesses tangible and intangible benefits as follows a ISO controls improve the information systems availability and reduce the risk of vulnerabilities being exploited while increasing the reliability and security of systems b Periodic audits and re certification process helps to keep the security controls up to date with while taking into account the latest vulnerabilities and best practices c The ISO compliance ensures the organisation that they can be trusted to secure customer s data as well as their own This increases customer confidence which in return gives more business more revenues and profits d Cost effective and consistent information security policies procedures and practices helps organisations to meet and exceed industry standards e Information systems can be prioritised to meet business requirements f Compliance with legislations g ISO defines the responsibilities and duties in line with operational processes and therefore strengthens internal organization h Attaining ISO 27001 certification demonstrates the preservation of confidentiality integrity and availability of the critical business information systems i Improved management control and security leadership j Improved risk management and contingency planning The ISO 27001 compliance provides a more structured approach to risk management This risk assessment identifies the assets which are critical to business This enables to have a better business continuity plan which prioritises the assets and reduces the potential exposure to financial loss or negative publicity In summary by complying to ISO IEC27001 an organisation can improve their security posture and demonstrate that their information assets are well protected and maintained This raises confidence among all interested parties and enable a safer and resilient business and operational environment Cyber Intelligence Sdn Bhd has developed an industry leading ISO IEC27001 compliance and implementation solution named CompSuite CompSuite aims to help organisations to go through a simplified structured and well informed way of implementing and managing ISO 27001 which includes project management document management learning management system security awareness risk assessment tool and more Raj Kumar MSc ISO27001 LA ABCP CISAM is Principal Security Consultant at Cyber Intelligence Sdn Bhd For more information please email to contactus cyberintelligence my

Vorschau MGCC Perspectives September/October 2016 Seite 23
Hinweis: Dies ist eine maschinenlesbare No-Flash Ansicht.
Klicken Sie hier um zur Online-Version zu gelangen.