What are iso 27001 ...
 
Notifications
Clear all

What are iso 27001 procedures?

1 Posts
1 Users
0 Reactions
470 Views
0
Topic starter

What are iso 27001 procedures?

1 Answer
0
Topic starter

ISO 27001 procedures are the detailed, step-by-step instructions that describe how an organization carries out its security policies. While a policy states the rules (the "what" and "why"), a procedure provides the hands-on guide for employees to follow. The standard itself doesn't provide a rigid list of mandatory procedures. Instead, it requires you to create the procedures necessary to support your Information Security Management System (ISMS) based on your specific risks and controls.

Key Characteristics

  • Action-Oriented: They are "how-to" guides for specific security tasks.

  • Detailed: They provide clear, step-by-step instructions.

  • Consistent: They ensure that tasks are performed in a repeatable and secure manner by everyone.

  • Auditable: They create a record that shows you are following your own rules, which is crucial for certification.

Common Examples of ISO 27001 Procedures

While not explicitly named, implementing the Annex A controls effectively requires creating procedures for many areas. Here are some of the most common ones:

  • Risk Assessment Procedure: Describes the step-by-step process for how your organization will identify, analyze, and evaluate information security risks.

  • Internal Audit Procedure: Outlines how you will plan, conduct, and report on internal audits to check the effectiveness of your ISMS.

  • Access Control Procedure: Details the process for granting, reviewing, and revoking user access to systems and data. This would include steps for new hires, role changes, and terminations.

  • Backup and Recovery Procedure: Provides instructions on how to perform data backups, how often, where to store them, and the exact steps to restore data in case of an incident.

  • Incident Management Procedure: Defines the step-by-step actions to take when a security incident (like a data breach or malware attack) occurs, from detection and containment to recovery and post-incident analysis.

  • Secure Disposal Procedure: Lays out the specific methods for securely destroying sensitive information, whether it's on a hard drive, a USB stick, or a paper document.

  • Change Management Procedure: Describes the process for managing changes to IT systems, applications, or networks to ensure security is not compromised.

Share:

Log in

You dont have an account yet? Register Now