<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Quality News &#187; ISO 27000</title>
	<atom:link href="http://quality-news.com/tag/iso-27000/feed/" rel="self" type="application/rss+xml" />
	<link>http://quality-news.com</link>
	<description>News about ISO standards and Quality Management</description>
	<lastBuildDate>Mon, 01 Feb 2010 15:36:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Why ISO 27001 is not enough</title>
		<link>http://quality-news.com/394/why-iso-27001-is-not-enough/</link>
		<comments>http://quality-news.com/394/why-iso-27001-is-not-enough/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 13:28:55 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[iso 27001]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=394</guid>
		<description><![CDATA[Since its publication in October 2005, ISO 27001 has been implemented in many organisations as the best practice for information security management, with over three hundred UK organisations independently certified against the standard.
So if these organisations, which range from small and medium to large enterprises, have implemented ISO 27001, why are we still hearing about [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_158" class="wp-caption alignleft" style="width: 144px"><img class="size-full wp-image-158" title="Infromation security" src="http://quality-news.com/wp-content/uploads/2009/06/security300x350.jpg" alt="Infromation security" width="134" height="156" /><p class="wp-caption-text">Infromation security</p></div>
<p>Since its publication in October 2005, ISO 27001 has been implemented in many organisations as the best practice for information security management, with over three hundred UK organisations independently certified against the standard.</p>
<p>So if these organisations, which range from small and medium to large enterprises, have implemented ISO 27001, why are we still hearing about lapses in information security? Neil O&#8217;Connor, principal consultant, Activity asks what lessons are there to be learnt from every organisation, whatever its size, using ISO 27001 as a benchmark?</p>
<p>Introduction</p>
<p>Information security, and in particular the handling of personal information, has regularly been in the headlines over the last few months. There have been notable incidents at HM Revenue and Customs, the Ministry of Defence, Nationwide Building Society and Marks and Spencer among others.<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br></p>
<p>These are all large organisations implementing information security management systems at least compliant with, if not certified against, the international standard for information security management, ISO 27001.</p>
<p>ISO27001<br />
<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br><br />
A key issue is that ISO 27001 is a management standard, not a security standard. It provides a framework for the management of security within an organisation, but does not provide a &#8216;Gold Standard&#8217; for security, which, if implemented, will ensure the security of an organisation.</p>
<p>ISO 27001 takes a risk assessment based approach. An information security risk assessment is used to identify the security requirements of the organisation, and to then identify the security controls needed to bring that risk within an acceptable level for the organisation.</p>
<p>Once the security controls have been identified, ISO 27001 defines processes to ensure that a) these controls are implemented and are effective; and b) that the controls continue to meet the organisation&#8217;s security needs.</p>
<p>read full text <a href="http://www.bcs.org/server.php?show=ConWebDoc.26594">on bcs.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/394/why-iso-27001-is-not-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>overview of information security management systems</title>
		<link>http://quality-news.com/157/overview-of-information-security-management-systems/</link>
		<comments>http://quality-news.com/157/overview-of-information-security-management-systems/#comments</comments>
		<pubDate>Sun, 07 Jun 2009 19:35:54 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[17799]]></category>
		<category><![CDATA[ISO STANDARD]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=157</guid>
		<description><![CDATA[With more and more organizations implementing information security management systems (ISMS) as part of their risk management strategy, the publication of a new ISO/IEC standard giving an overview of ISMS is particularly timely.
Information securityISO/IEC 27000:2009, Information technology – Security techniques – Information security management systems – Overview and vocabulary, will assist organizations of all types [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_158" class="wp-caption aligncenter" style="width: 310px"><img class="size-full wp-image-158" title="Infromation security" src="http://quality-news.com/wp-content/uploads/2009/06/security300x350.jpg" alt="Infromation security" width="300" height="350" /><p class="wp-caption-text">Infromation security</p></div>
<p>With more and more organizations implementing information security management systems (ISMS) as part of their risk management strategy, the publication of a new ISO/IEC standard giving an overview of ISMS is particularly timely.</p>
<p>Information securityISO/IEC 27000:2009, Information technology – Security techniques – Information security management systems – Overview and vocabulary, will assist organizations of all types to understand the fundamentals, principles and concepts to improve protection of their information assets.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Applicable to all types and sizes of organization (e.g. commercial enterprises, government agencies, non-profit organizations), ISO/IEC 27000:2009 supplements the ISO/IEC 27000 family of standards by providing an introduction to information security management and defining related terms.</p>
<p>Today, an organization&#8217;s information assets are dependent upon information and communications technology. The technology assists in facilitating the creation, processing, storing, transmitting, protection and destruction of information.</p>
<p>As the extent of the interconnected global business environment expands, so does the requirement to protect information as it is exposed to a wider variety of threats and vulnerabilities.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
Edward Humphreys, convenor of the working group, which developed the standard, comments: &#8220;Standardized security techniques are becoming mandatory requirements for e-commerce, health-care, telecoms, automotive and many other application areas in both the commercial and government sectors. ISO/IEC 27000:2009, together with the other ISO/IEC 27000 family of standards, aims to assist organizations more effectively achieve an appropriate level of information security.&#8221;</p>
<p>red full story <a href="http://www.iso.org/iso/pressrelease.htm?refid=Ref1223">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/157/overview-of-information-security-management-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISO-27001 Certification Process</title>
		<link>http://quality-news.com/145/iso-27001-certification-process/</link>
		<comments>http://quality-news.com/145/iso-27001-certification-process/#comments</comments>
		<pubDate>Sat, 06 Jun 2009 20:07:37 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[ISO Standards]]></category>
		<category><![CDATA[ISO STANDARD]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=145</guid>
		<description><![CDATA[The process starts when the organization makes the decision to embark upon the exercise. Clearly, at this point, it is also important to ensure management commitment and then assign responsibilities for the project itself.
An organizational top level policy can then be developed and published. This can, and will normally, be supported by subordinate policies. The [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_146" class="wp-caption aligncenter" style="width: 434px"><img class="size-full wp-image-146" title="risk13e" src="http://quality-news.com/wp-content/uploads/2009/06/risk13e.gif" alt="risk13e" width="424" height="404" /><p class="wp-caption-text">ISO 27000</p></div>
<p>The process starts when the organization makes the decision to embark upon the exercise. Clearly, at this point, it is also important to ensure management commitment and then assign responsibilities for the project itself.</p>
<p>An organizational top level policy can then be developed and published. This can, and will normally, be supported by subordinate policies. The next stage is particularly critical: scoping. This will define which part(s) of the organization will be covered by the ISMS. Typically, it will define the location, assets and technology to be included.<br />
<br /><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN crno bijela 400x60 */
google_ad_slot = "6523180554";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br /><br />
At this stage a risk assessment will be undertaken, to determine the organization&#8217;s risk exposure/profile, and identify the best route to address this. The document produced will be the basis for the next stage, which will be the management of those risks. A part of this process will be selection of appropriate controls with respect to those outlined in the standard (and ISO27002), with the justification for each decision recorded in a Statement of Applicability (SOA). The controls themselves should then be implemented as appropriate.</p>
<p>read full story <a title="ISO 27000" href="http://www.27000.org/ismsprocess.htm" target="_blank">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/145/iso-27001-certification-process/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An Introduction To ISO 27001 (ISO27001)</title>
		<link>http://quality-news.com/11/an-introduction-to-iso-27001-iso27001/</link>
		<comments>http://quality-news.com/11/an-introduction-to-iso-27001-iso27001/#comments</comments>
		<pubDate>Sun, 31 May 2009 21:01:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[17799]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=11</guid>
		<description><![CDATA[An Introduction To ISO 27001 (ISO27001)
The ISO 27001 standard was published in October 2005, essentially replacing the old BS7799-2 standard. It is the specification for an ISMS, an Information Security Management System. BS7799 itself was a long standing standard, first published in the nineties as a code of practice. As this matured, a second part [...]]]></description>
			<content:encoded><![CDATA[<h1>An Introduction To ISO 27001 (ISO27001)</h1>
<p>The ISO 27001 standard was published in October 2005, essentially replacing the old BS7799-2 standard. It is the specification for an ISMS, an Information Security Management System. BS7799 itself was a long standing standard, first published in the nineties as a code of practice. As this matured, a second part emerged to cover management systems. It is this against which certification is granted. Today in excess of a thousand certificates are in place, across the world. <a href="http://www.27000.org/iso-27001.htm">read more</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/11/an-introduction-to-iso-27001-iso27001/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
