he ISO 17799 standard gives recommendations for
information security management and is available to
those responsible for initiating, implementing or
maintaining security in their organization. ISO 17799 is
"a comprehensive set of controls comprising best
practices in information security", essentially an
internationally recognized generic information security
standard.
Information security is achieved by
implementing a suitable set of controls, such as:
policies, processes, procedures, organizational
structures and software and hardware functions. These
controls need to be established, implemented, monitored,
reviewed, improved and reported on to ensure that the
specific security and business objectives of the
organization are met.
ISO 17799 establishes guidelines and general
principles for initiating, implementing, maintaining and
improving information security management in an
organization. ISO 17799 contains best practices of IT
control objectives in the following areas of information
security management:
- security policy;
- organization of information security;
- asset management;
- human resources security;
- physical and environmental security;
- communications and operations management;
- access control;
- information systems acquisition, development and
maintenance;
- information security incident management;
- business continuity management;
- compliance
Once implemented, the control objectives of ISO 17799
are intended to meet the requirements identified by a
risk assessment. ISO17799 is intended to be a common
basis as well as a practical guideline for developing
organizational security standards and effective security
management practices.
Key Benefits