Solved

Design a network compliant with ISO 27001 ???

Posted on 2006-10-25
2
338 Views
Last Modified: 2010-04-11
Hi Experts,

I need to design a network with couple of servers with WAN, LAN, PSTN with compliant with ISO 27001.
What are the guide lines for this ?? Please pull me some resources.

Please advice !

Thanks a lot !
0
Comment
Question by:NetMaxtor
2 Comments
 
LVL 18

Accepted Solution

by:
PowerIT earned 500 total points
ID: 17802123
Hi,

ISO 27001 is about "Information Security Management Systems Requirements" (ISMS)
Then there is ISO 17799 which is the "Code of Practice for information security management". This is a best practice and will be renamed to ISO 27002 in the future.
Both originate from BS-7999.
27001 used to be part 2 and 27002 used to be part one.
A little confusing eh?
Let me clarify:
ISO 27001 is a process approach to implement the controls defined in ISO 17799 (27002).
So you will need both. The process is as following:
1) Define an information security policy
2) Define scope of the information security management system
3) Perform a security risk assessment
4) Manage the identified risk
5) Select controls to be implemented and applied (ISO 17799)
6) Prepare an SoA (a "statement of applicability")

You can buy the ISO standard documents here:
https://eshop.bsi-global.com/ProductListing.aspx?cat=InformationTechnology%2fInformationSecurity
But, don't try to take this to the letter and implement all.
For the auditors, you do not need to implement every control. You have to keep it pragmatic and look at your business.
And then be able to document why you have exceptions.
Also: start small. Implementing this is typically a 3 years project.
So start with the basic and a simple policy. Next year go further etc ...
Auditors understand this. They will start with the basics and request more advanced controls and process for the next year.
Keep it practical, no user or manager will read a policy of 300 pages ...

For a quick start, SANS has a free checklist here: http://www.sans.org/score/checklists/ISO_17799_2005.doc

Also see:
- http://www.iso27001security.com/
- http://www.17799.com/ (a discussion forum)

J.
0
 

Author Comment

by:NetMaxtor
ID: 17802152
Thanks a lot !
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now