<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Quality News &#187; iso 27001</title>
	<atom:link href="http://quality-news.com/tag/iso-27001/feed/" rel="self" type="application/rss+xml" />
	<link>http://quality-news.com</link>
	<description>News about ISO standards and Quality Management</description>
	<lastBuildDate>Fri, 16 Dec 2011 12:29:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Why ISO 27001 is not enough</title>
		<link>http://quality-news.com/394/why-iso-27001-is-not-enough/</link>
		<comments>http://quality-news.com/394/why-iso-27001-is-not-enough/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 13:28:55 +0000</pubDate>
		<dc:creator>QualityGuru</dc:creator>
				<category><![CDATA[ISO 27000]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[iso 27001]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://quality-news.com/?p=394</guid>
		<description><![CDATA[Since its publication in October 2005, ISO 27001 has been implemented in many organisations as the best practice for information security management, with over three hundred UK organisations independently certified against the standard. So if these organisations, which range from small and medium to large enterprises, have implemented ISO 27001, why are we still hearing [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_158" class="wp-caption alignleft" style="width: 144px"><img class="size-full wp-image-158" title="Infromation security" src="http://quality-news.com/wp-content/uploads/2009/06/security300x350.jpg" alt="Infromation security" width="134" height="156" /><p class="wp-caption-text">Infromation security</p></div>
<p>Since its publication in October 2005, ISO 27001 has been implemented in many organisations as the best practice for information security management, with over three hundred UK organisations independently certified against the standard.</p>
<p>So if these organisations, which range from small and medium to large enterprises, have implemented ISO 27001, why are we still hearing about lapses in information security? Neil O&#8217;Connor, principal consultant, Activity asks what lessons are there to be learnt from every organisation, whatever its size, using ISO 27001 as a benchmark?</p>
<p>Introduction</p>
<p>Information security, and in particular the handling of personal information, has regularly been in the headlines over the last few months. There have been notable incidents at HM Revenue and Customs, the Ministry of Defence, Nationwide Building Society and Marks and Spencer among others.<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br></p>
<p>These are all large organisations implementing information security management systems at least compliant with, if not certified against, the international standard for information security management, ISO 27001.</p>
<p>ISO27001<br />
<br><script type="text/javascript"><!--
google_ad_client = "pub-3252843659449994";
/* QN 360 */
google_ad_slot = "9582838922";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br><br />
A key issue is that ISO 27001 is a management standard, not a security standard. It provides a framework for the management of security within an organisation, but does not provide a &#8216;Gold Standard&#8217; for security, which, if implemented, will ensure the security of an organisation.</p>
<p>ISO 27001 takes a risk assessment based approach. An information security risk assessment is used to identify the security requirements of the organisation, and to then identify the security controls needed to bring that risk within an acceptable level for the organisation.</p>
<p>Once the security controls have been identified, ISO 27001 defines processes to ensure that a) these controls are implemented and are effective; and b) that the controls continue to meet the organisation&#8217;s security needs.</p>
<p>read full text <a href="http://www.bcs.org/server.php?show=ConWebDoc.26594">on bcs.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://quality-news.com/394/why-iso-27001-is-not-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced

Served from: quality-news.com @ 2012-02-04 23:48:15 -->
