ISO 27001 Annex : A.11.1.3, A.11.1.4 , A.11.1.5 & A.11.1.6


In this article explained ISO 27001 Annex : A.11.1.3 Securing Offices Rooms and Facilities, A.11.1.4 Protecting Against External and Environmental Threats, A.11.1.5 Working in Secure Areas, A.11.1.6 Delivery and Loading Areas.
A.11.1.3 Securing Offices, Rooms and Facilities
Control- Physical security should be designed and implemented for the offices, rooms, and facilities.
Implementation Guidance- The following guidelines for safeguarding offices, spaces, and services should be considered:
  1. Key facilities should be situated to avoid public access;
  2. The presence of the information processing activities should be indicated unobtrusively where appropriate and offer a minimum indication of their intent and no obvious signs outside or inside the building;
  3. In order to avoid sensitive information or events that are visible and audible outside, facilities should be installed. Electromagnetic security should also be taken into account as appropriate;
  4. Directories and internal telephone books which identify sites where confidential information processing facilities should not be readily available to unauthorized persons.
A.11.1.4 Protecting Against External and Environmental Threats
Control- Physical protection should be designed and applied against natural disasters, malicious attacks or accidents.
Implementation Guidance- Specialized advice on how to prevent fire damage, flood, earthquake, blast, civil disaster and other types of natural or man-made disaster.
“ When you gambled with safety, you bet your life”
The Organization wishes that its information to remain within the CIA triads. They also ensure that the physical security controls are properly and efficiently implemented to protect the confidentiality, authenticity and/or integrity of the organization’s information and information processing facilities. The physical and environmental protection of the company is covered in Annex 11 of ISO 27002 . This famous certification of lead auditor and lead implementer covers all the annexes to the security of information by implementing appropriate access controls to ensure authorized access to protect the organization. Infosavvy , a Mumbai-based institute, offers certifications and training for multiple-domain-like management of information security, cybersecurity, and many others, including the IRCA CQI ISO 27001:2013 Lead Auditor (LA) and ISO 27001 Lead Implementer (LI) (TÜV SÜD Certification). This certification covers several audits to keep an organization safe from the intended destructor. Infosavvy will help you to understand and identify the full extent of the physical and environmental security of your organization that is necessary to protect the operations of your organization from attacks. We have trained trainers who have ample know-how and experience in order to make sure that the information security is effectively handled. The applicant will, therefore, gain the skills needed to conduct the ISMS audit using commonly agreed audit concepts, procedures and techniques
INFORMATION SECURITY ISO 27001 LEAD AUDITOR CERTIFICATION
A.11.1.5 Working in Secure Areas
Control- Procedures should be designed and implemented for working in safe areas.
Implementation Guidance- The following guidelines should be taken into account:
  1. Workers can only know on a need to know basis the presence of activities within a secure area;
  2. Unattended work in safe areas, both for reasons of safety and to prevent malicious activities opportunities should be avoided;
  3. Vacant secure areas should be physically closed and periodically reviewed;
  4. Photographic, video, audio or other recording equipment, such as cameras on mobile devices, should not be allowed unless it is authorized to do so.
Safe-area work arrangements provide safeguards for employees and external party users operating in a secure area that include all activities taking place in a secure area.
A.11.1.6 Delivery and Loading Areas
Control- It is important to track and, where possible, differentiate between access points such as the distribution and loading areas and other locations in order to avoid unauthorized access by unauthorized persons to the premises.
Implementation guidance- The following guidelines should be taken into account:
  1. Identified and authorized personnel should restrict access to the delivery area and the loading area from outside the building;
  2. The supply and loading area should be designed so as to allow the loading and unloading of the supplies without access to other parts of the building by delivery personnel;
  3. When opening the interior doors, external doors of a storage and storage area should be secured;

--------------------------------------------------------------------------------------------------------------------------

This Blog Article is posted by
Infosavvy, 2nd Floor, Sai Niketan, Chandavalkar Road Opp. Gora Gandhi Hotel, Above Jumbo King, beside Speakwell Institute, Borivali West, Mumbai, Maharashtra 400092
Contact us – www.info-savvy.com

Comments

  1. Excellent blog! I read your blog and it’s really impressive that you mainly stress the quality management word. Thank for sharing this blog. This type of blogs is always appreciated.iso lead auditor training in india

    ReplyDelete
  2. Wow, so amazing reasons that you have shared here & this will be must helpful for all. ISO 9001 Lead Auditor Course Qatar

    ReplyDelete
  3. Thanks for given detail information to me. keep posting like this. iso-45001-2018

    ReplyDelete
  4. Thanks you for sharing this unique useful information content with us. Really awesome work.ISO 27001 certification

    ReplyDelete

Post a Comment

Popular posts from this blog

10 Secrets You Will Never Know About Cyber Security And Its Important

ISO 27001 Annex : A.5 Information Security Policies

Impact Of ISO 27001 Lead Auditor