Subject

Information security is defined as preservation of confidentiality, integrity and availability of information (ISO/IEC 27000), while:

  • confidentiality is a property that information is not made available or disclosed to unauthorized individuals, entities, or processes
  • integrity is a property of accuracy and completeness
  • availability is a property of being accessible and usable on demand by an authorized entity

Applied standards

ISO/IEC 27001 provides requirements for establishing, implementing, maintaining and continually improving an information security management system. The adoption of an information security management system is a strategic decision for an organization. The establishment and implementation of an organization’s information security management system is influenced by the organization’s needs and objectives, security requirements, the organizational processes used and the size and structure of the organization. All of these influencing factors are expected to change over time.

The information security management system preserves the confidentiality, integrity and availability of information by applying a risk management process and gives confidence to interested parties that risks are adequately managed.

It is important that the information security management system is part of and integrated with the organization’s processes and overall management structure and that information security is considered in the design of processes, information systems, and controls. It is expected that an information security management system implementation will be scaled in accordance with the needs of the organization.

This document can be used by internal and external parties to assess the organization’s ability to meet the organization’s own information security requirements.

The order in which requirements are presented in this document does not reflect their importance or imply the order in which they are to be implemented. The list items are enumerated for reference purpose only.

Our services

The SSA is planning to provides high quality services of Certification of information security management system based on ISO/IEC 27001. The service will include a complex of onsite and off-site assessment of how organisation established, implemented, maintained and continually improved an information security management system.