18.12.2012 Views

Proceedings

Proceedings

Proceedings

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ISMS Process<br />

(Source: Applying ISO 27000 in business strategies)<br />

4.2. Managing the implementation of ISMS according to ISO 27001<br />

An ISMS (Information Security Management System) is a management system based<br />

on a systemic approach to the risks to which the company is exposed to and aims to<br />

establish, implement, operate, monitor, review, maintain and improve information<br />

security policies, information systems and personnel.<br />

Entities which considered that the information in the framework of the activities and<br />

not only, must be protected, should have a management system to control the risks<br />

arising from all levels of access. According to the ISO 27001 (ISACA, 2008), keeping<br />

information by implementing a management system and certification of information<br />

security, it will represent the business card of the organization for customers and<br />

business partners.<br />

~ 673 ~

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!