Tuesday, May 04, 2021

What are ISO 27001 requirements?

What are ISO 27001 requirements?


In this particular video I'm going to be focusing in on the

10 most common questions of ISO 27001 the third most common questions that gets asked on google and also of us here at best practice is what are the requirements well the requirements are here in the standard it's not a

very big document you can see in its printed form it's not huge what we can go to is we go to the contents page which is here which asks what the requirements are so it basically says there's  requirement.


ISO 27001 Requirements
To understand the context of your organization there's a requirement to have leadership commitment and have leadership set some Policies and leadership create organizational roles and responsibilities there's a requirement to do planning around cyber security and planning you know thinking about risks thinking about opportunities thinking about objectives and goals and doing some planning there's a requirement to put some resources in place so resources training awareness.

 

Communications some documented information in place is a requirement to do some doing there's a requirement to operate your business and and to be checking in on how you know the controls you put in place for the risks you identified are they being implemented there's a requirement here to manage to monitor your performance like any good weight loss program getting on the scales and measure doing some measurements to see how your tracking is important and and these standards are no different they talk about performance evaluation and in fact. 

 

If you look at our logos here at best practice they are a performance over time graph because we're trying to encourage you to have like triple bottom line reporting or quadruple or 10 point bottom line reporting so that you've got you know a dashboard.

So there's a requirement there to have monitoring and measurement analysis and evaluation some do some internal audits and do some strategic planning and have management reviews and there's obviously a requirement there to have improvement and do can you know corrective and preventive action and improvements there so those are the ISO 27001 requirements uh what's involved there are 10 sections to the standard and each of the ISO standards for management systems all have those 10 sections now they all follow a similar format.

 

   Watch this video on 

Using PCI DSS for ISO 27001 Compliance

 


1 comment:

  1. How to Check if a Website OR URL is Safe or Not? Cyber security
    🔒🔓

    http://www.urlhelp.xyz/2021/07/how-to-check-if-website-or-url-is-safe.html

    I am from internet data search help service

    https://www.urlhelp.xyz/

    ReplyDelete

Understanding SOC 2 Type 1 vs. Type 2: A Comprehensive Guide

  In today's rapidly evolving digital landscape, organizations are under constant pressure to demonstrate their commitment to security, ...