ISO17799 - Broken Down
Business Continuity Planning
To counteract interruptions to business activities and to critical
business processes from the effects of major failures or disasters.
System Access Control
The objectives of this section are:
- To control access to information
- To prevent unauthorised access to information systems
- To ensure the protection of networked services
- To prevent unauthorised computer access
- To detect unauthorised activities.
- To ensure information security when using mobile computing
and tele-networking facilities
System Development &
Maintenance
The objectives of this section are:
- To ensure security is built into operational systems
- To prevent loss, modification or misuse of user data in
application systems
- To protect the confidentiality, authenticity and integrity
of information
- To ensure IT projects and support activities are conducted
in a secure manner
- To maintain the security of application system software
and data.
Physical & Environmental
Security
The objectives of this section are:
- To prevent unauthorised access, damage and interference
to business premises and information
- To prevent loss, damage or compromise of assets and interruption
to business activities
- To prevent compromise or theft of information and information
processing facilities.
Compliance
The objectives of this section are:
- To avoid breaches of any criminal or civil law, statutory,
regulatory or contractual obligations and of any security
requirements.
- To ensure compliance of systems with organisational security
policies and standards.
- To maximise the effectiveness of and to minimise interference
to/from the system audit process.
Personal Security
The objectives of this section are:
- To reduce risks of human error, theft, fraud or misuse of
facilities
- To ensure that users are aware of information security threats
and concerns, and are equipped to support the corporate security
policy in the course of their normal work.
- To minimise the damage from security incidents and malfunctions
and learn from such incidents.
Security Organisation
The objectives of this section are:
- To manage information security within the Company
- To maintain the security of organisational information processing
facilities and information assets accessed by third parties.
- To maintain the security of information when the responsibility
for information processing has been outsourced to another
organisation.
Computer & Network
Management
The objectives of this section are:
- To ensure the correct and secure operation of information
processing facilities
- To minimise the risk of systems failures
- To protect the integrity of software and information
- To maintain the integrity and availability of information
processing and communication
- To ensure the safeguarding of information in networks and
the protection of the supporting infrastructure
- To prevent damage to assets and interruptions to business
activities
- To prevent loss, modification or misuse of information exchanged
between organisations.
Asset Classification and
Control
To maintain appropriate protection of corporate assets and
to ensure that information assets receive an appropriate level
of protection.
Security Policy
To provide management direction and support for information
security.
|