1.Customer focus
2.Leadership
3.Involvement of people
4.Process approach
5.System approach to management
6.Continual improvement
7.Factual approach to decision making
8।Mutually beneficial supplier relationships
फॉर मोरे ईन्फ़ोर्मतिओन विसित उस अत "ह्त्त्प://व्व्व.इसोकेर्तिफ़िकतिओनसिअ.कॉम"
Monday, December 6, 2010
Quality management systems
ISO 9001 Certification is a Quality Management System Standard. It applies to all types of organizations. It doesn’t matter what size they are or what they do. It can help both product and service oriented organizations achieve standards of quality that are recognized and respected throughout the world.
Tuesday, September 22, 2009
- Best iso consultant,
- good consltant,
- HACCP ISO 22000,
- how to find ISO consultant,
- ISO 14001,
- ISO 27001,
- ISO 9001,
- ISO certificate consultant,
- ISO certification,
- ISO Consultant,
- OHSAS 18001,
- SA 8000
- HACCP ISO 22000,
- ISO 14001,
- ISO 27001,
- OHSAS 18001,
- SA 8000,
- iso 9001 implementation
Thursday, September 10, 2009
Dextrys Achieves ISO 27001 Security Certification
Dextrys, a US-based China outsourcing firm delivering Product Engineering and Application Services has achieved ISO 27001 certification for its information security management system – specifically, design, development, testing and maintenance of all software.
Monday, March 30, 2009
How ISO 27001:2005 works
ISO/IEC 27001:2005 covers twelve sections:
- Security Policy
- Organisation of Information Security
- Asset Management
- Human Resources Security
- Physical and Environmental Security
- Communications and Operations
- Management
- Access Control
- Information Systems Acquisition, Development and Maintenance
- Information Security Incident Management
- Business Continuity Management
- Compliance
Saturday, February 28, 2009
Style Of Delivery And Course Leaders
our course leaders are business improvement professionals. They have extensive hands-on experience of leading change in a wide range of sectors including manufacturing, finance, pharmaceuticals, local and national government. They have all, at one time or another, applied the full range of the most successful business improvement models and techniques around at the moment, including ISO 9000, the EFQM Model, Investors in People, Total Quality Management and Six Sigma.
Monday, February 16, 2009
Why use the Hosted Business Model?
We emphasis the Business rather than just the Security or IT part of ISO 27001. Instead of many Polices, Procedure and Work Instructions (one system we converted had over 80 Work Instructions which was completely unworkable). We concentrate on an integrated solution.
Note – ISO 27001 should not be dominated by IT requirements since it relates to all Company information. Nor should the controls and processes be dominated by only Security issues since the Standard relates to Risk Management associated to the:
Note – ISO 27001 should not be dominated by IT requirements since it relates to all Company information. Nor should the controls and processes be dominated by only Security issues since the Standard relates to Risk Management associated to the:
What is the actual definition of "ISO Certification"?
The International Organization for Standardization headquartered in Geneva, Switzerland is the world's largest developer and publisher of International Standards, many that describe the best practices of private industry and government. Over 157 countries including the United States have adopted ISO standards as their own. After a rigorous review of our facility, practices, and technology, TeleDirect was certified in November for this prestigious distinction. This means that TeleDirect adheres to strict guidelines for the protection of your data and continuously strives to improve those safeguards. By earning ISO 27001 certification we have further demonstrated our commitment to making our Company more secure and securing your information.
Attestation 27001
The ISO 27001 security standard requires the implementation of an Information Security Management System (ISMS).
The necessary control objectives are not only implemented but also operated, monitored, controlled, maintained and improved.
The standard requires the company's IT operations to maintain the following qualities:
The necessary control objectives are not only implemented but also operated, monitored, controlled, maintained and improved.
The standard requires the company's IT operations to maintain the following qualities:
- Confidentiality: information for identified, authorized persons
- Integrity: information, methods and processes are precise and permanent
- Availability: systems and infrastructure are stable and available round-the-clock
Four costs need to be considered when implementing this type of project.
1. Internal resources - the system covers a wide range of business functions - management, HR, IT, facilities & security. These resources will be required during the implementation of an ISMS.
2. Consultancy resources - a experienced consultant will save a huge amount of time, an will often challenge you on the implications of the controls you select. They will also prove a useful tool during internal audits where our independence and Lead Auditor status will ensure smooth transition towards certification. Contact us and we can give you a better picture of our costs. Typically look for 20-30 days work at similar rates to other IT consultants / professional services.
3. Certification costs - only a few certification bodies currently assess companies against ISO 27001, but fees are not much more than against other standards eg ISO 9001 or ISO 14001.
4. Implementation costs - this cannot be estimated by us. If, as a result of a risk assessment, or audit, a gap appears in your system and you feel the best way to address the risk is to buy a better firewall for example, it could be construed as an implementation cost.
2. Consultancy resources - a experienced consultant will save a huge amount of time, an will often challenge you on the implications of the controls you select. They will also prove a useful tool during internal audits where our independence and Lead Auditor status will ensure smooth transition towards certification. Contact us and we can give you a better picture of our costs. Typically look for 20-30 days work at similar rates to other IT consultants / professional services.
3. Certification costs - only a few certification bodies currently assess companies against ISO 27001, but fees are not much more than against other standards eg ISO 9001 or ISO 14001.
4. Implementation costs - this cannot be estimated by us. If, as a result of a risk assessment, or audit, a gap appears in your system and you feel the best way to address the risk is to buy a better firewall for example, it could be construed as an implementation cost.
ISO 27001/ISO 17799 Audit Questions and Checklist
Below sample question that yout can find in the ISO7799 Audit Questions and Checklist. The excel list also could be downloaded below
- Whether there exists an Information security policy, which is approved by the management, published and communicated as appropriate to all employees.
- Whether it states the management commitment and set out the organisational approach to managing information security. Whether the Security policy has an owner, who is responsible for its maintenance and review according to a defined review process.
- Whether the process ensures that a review takes place in response to any changes affecting the basis of the original assessment, example: significant security incidents, new vulnerabilities or changes to organisational or technical infrastructure.
- Whether there is a management forum to ensure there is a clear direction and visible management support for security initiatives within the organisation.
- Whether there is a cross-functional forum of management representatives from relevant parts of the organisation to coordinate the implementation of information security controls.
Achieving ISO 20000 with Business Beam
Business Beam offers expert consulting services for effective implementation of ISO20000.
- Awareness and Project Scoping: We start with ISO 20000 awareness trainings. We then define the scope of certification within your organization and confirm the eligibility for certification. We also propose an approach for how your organization should consider achieving and subsequently retaining ISO 20000.
- Capability Assessment: Capability Assessment is a rigorous snapshot of your service management capability against the standard. The assessment takes places via a combination of on-site visits, information gathering, off-site evidence reviews, clarification and elaboration interviews culminating in a final comprehensive assessment report.
- Gap Closure: Following on from the capability and gap assessment we work with your teams to discuss the gaps, the relevance of the closure activities and the time frames in which these will be completed. We then draw up a project plan and project initiation document to address every gap in a realistic timescale. RAID assessments are also undertaken (Risks, Assumptions, Issues and Dependencies).
ISO 20000 scope
ISO 20000 itself is not clear on scoping. It says, simply, that it defines ‘the requirements for a service provider to deliver managed services of an acceptable quality for its customers.’ This statement is so broad that it might appear that virtually any organization that delivers managed services to customers would be eligible for ISO 20000 certification.
It is necessary to turn to the additional, published guidance on ISO 20000 scoping to clarify the requirements. Clause 1 of these guidelines says: “in order for a Service Provider organization to achieve certification under the ISO/IEC 20000 scheme it must be able to demonstrate that it has ‘management control’ of all the processes defined within the ISO/IEC 20000 standard. For this purpose, ‘management control’ of a process consists of:
It is necessary to turn to the additional, published guidance on ISO 20000 scoping to clarify the requirements. Clause 1 of these guidelines says: “in order for a Service Provider organization to achieve certification under the ISO/IEC 20000 scheme it must be able to demonstrate that it has ‘management control’ of all the processes defined within the ISO/IEC 20000 standard. For this purpose, ‘management control’ of a process consists of:
- Knowledge and control of inputs;
- Knowledge, use and interpretation of outputs;
- Definition and measurement of metrics;
- Demonstration of objective evidence of accountability for process functionality in conformance to the ISO/IEC 20000 standard; and
- Definition, measurement and review of process improvements.”
This two-day course is designed for professionals...
- who are familiar with ISO 27001/27002
- who are looking for guidance on auditing against the ISO 27002 standards
- who plan to adopt the security framework and implement the standards
- who would like to see their organization certified to ISO 27001
- who would like to improve their security program and align their security goals to their business objectives
We recommend the following best practice guidelines to minimize the risks involved in credit card transactions:
* Ensure that credit cards used to purchase goods or services on the Internet have a low credit limit, or if debit cards are used, that they have limited funds and are only topped up to cover specific Internet purchases.
* All expenses incurred through Internet transactions should be carefully audited on a regular basis for any anomalies.
* Only enter credit card details on a Web site if you are confident as to its authenticity and that the connection is secure - the prefix https (as opposed to the usual http) in the Web Site address indicates a secure connection.
* If the security of a Web site is in doubt, any confidential information posted to it may be exposed to malicious intent. Be extremely cautious when posting confidential details on any site where the Internet Service Provider hosting the site is not verified. Note that we have pre-checked all sites referenced in this newsletter for security!
* All expenses incurred through Internet transactions should be carefully audited on a regular basis for any anomalies.
* Only enter credit card details on a Web site if you are confident as to its authenticity and that the connection is secure - the prefix https (as opposed to the usual http) in the Web Site address indicates a secure connection.
* If the security of a Web site is in doubt, any confidential information posted to it may be exposed to malicious intent. Be extremely cautious when posting confidential details on any site where the Internet Service Provider hosting the site is not verified. Note that we have pre-checked all sites referenced in this newsletter for security!
SOCIAL ENGINEERING - ARE YOU SUSCEPTIBLE?
The term 'social engineering' can conjure up a variety of ideas, usually based around the concept of genetic tampering. However, when applied to IT security, it has its own implications and its own vocabulary.
Following interviews with known computer criminals, a list of approaches has been produced. These are designed to gather information without the target even realizing that they have parted with it. The attempts are often made on an opportune bases, with common locations for this sort of activity being planes, trains and pubs. The telephone is probably the major source of pre-meditated acts.
Following interviews with known computer criminals, a list of approaches has been produced. These are designed to gather information without the target even realizing that they have parted with it. The attempts are often made on an opportune bases, with common locations for this sort of activity being planes, trains and pubs. The telephone is probably the major source of pre-meditated acts.
Structure and format of ISO/IEC 27002
ISO/IEC 27002 is a code of practice - a generic, advisory document, not truly a standard or formal specification such as ISO/IEC 27001. It lays out a well structured set of suggested controls to address information security risks, covering confidentiality, integrity and availability aspects. Organizations that adopt ISO/IEC 27002 must assess their own information security risks and apply suitable controls, using the standard for guidance. Strictly speaking, none of the controls are mandatory but if an organization chooses not to adopt something as common as, say, antivirus controls, they should certainly be prepared to demonstrate that this decision was reached through a rational risk management decision process, not just an oversight, if they anticipate being certified compliant to ISO/IEC 27001.
Scope of ISO/IEC 27002
Like governance, information security is a broad topic with ramifications in all parts of the modern organization. Information security, and hence ISO/IEC 27002, is relevant to all types of organization including commercial enterprises of all sizes (from one-man-bands up to multinational giants), not-for-profits, charities, government departments and quasi-autonomous bodies - in fact any organization that handles and depends on information. The specific information security requirements may be different in each case but the point of ISO/IEC 27002 is that there is a lot of common ground.
The standard is explicitly concerned with information security, meaning the security of information assets, and not just IT/systems security per se. The IT Department is merely the custodian of a good proportion of the organization’s information assets and is charged with securing them by the information asset owners - the business managers who are accountable for the assets. A large proportion of written and intangible information (e.g. the knowledge and experience of workers) is nothing to do with IT.
The standard is explicitly concerned with information security, meaning the security of information assets, and not just IT/systems security per se. The IT Department is merely the custodian of a good proportion of the organization’s information assets and is charged with securing them by the information asset owners - the business managers who are accountable for the assets. A large proportion of written and intangible information (e.g. the knowledge and experience of workers) is nothing to do with IT.
ISO/IEC 27002:2005 - the current, issued standard
ISO/IEC 17799:2005 was renumbered ISO/IEC 27002:2005 in the middle of 2007 to bring it into the ISO/IEC 27000 family of standards. The text remains word-for-word identical to ISO/IEC 17799:2005 - in fact, for some while the ISO/IEC 17799 standard continued to be delivered to anyone who ordered ISO/IEC 27002, along with a cover sheet noting the change of number.
THE CONTENTS OF ISO 17799 / 27002
The content sections are:
· Structure
· Risk Assessment and Treatment
· Security Policy
· Organization of Information Security
· Asset Management
· Human Resources Security
· Physical Security
· Communications and Ops Management
· Access Control
· Information Systems Acquisition, Development, Maintenance
· Information Security Incident management
· Business Continuity
· Structure
· Risk Assessment and Treatment
· Security Policy
· Organization of Information Security
· Asset Management
· Human Resources Security
· Physical Security
· Communications and Ops Management
· Access Control
· Information Systems Acquisition, Development, Maintenance
· Information Security Incident management
· Business Continuity
Subscribe to:
Posts (Atom)