Posts

Showing posts with the label Authentication

ISO 27001 Annex : A.14.1.2 Securing Application Services on Public Networks

Image
  Control-  ISO 27001 Annex : A.14.1.2 Securing Application Services on Public Networks  Information about application services which pass through public networks should be protected against fraudulent activities, contract disputes, unauthorized disclosure, and modification. Implementation Guidance –  Information security requirements will include the following for application services that cross public networks: Each party requires a level of trust in the identity claimed by each other, for example, through authentication; Authorizations  for those who may authorize the content of key transnational documents, issue or sign them; Ensure that  communication  parties are fully aware of their service provision or usage authorizations; Determination and compliance with the conditions of  confidentiality, integrity , proof that key documents and contracts, for instance, related to contracts and tendering process, have been dispatched and received; The ...

ISO 27001 Annex : A.13 Communications Security

Image
  ISO 27001 Annex : A.13 Communications Security in this article explain  A.13.1  Network Security Management,  A.13.1.1  Network Controls,  A.13.1.2  Security of Network Services,  A.13.1.3  Segregation in Networks. A.13.1  Network Security Management It’s objective is to ensure the security and supporting information processing facilities of the information in a network. A.13.1.1  Network Controls Control-  To protect  information in systems  and applications, networks should be managed and monitored. Implementation Guidance –  The monitoring of network  information security  and the security of connected networks from unauthorized access should be undertaken. The following things will in particular be taken into account: Networking  equipment management  responsibilities and procedures should be established; Network operational responsibility can, where necessary, be segregated from compute...

ISO 27001 Annex : A.10 Cryptography

Image
ISO 27001 Annex : A.10 Cryptography in this article explaining Cryptographic controls, Policy on the Utilization of Cryptographic Controls & Key Management. A.10.1 Cryptographic controls Its objective is to  ensure the proper and efficient use of cryptography to protect the confidentiality, authenticity and/or integrity of the information. A.10.1.1 Policy on the Utilization of Cryptographic Controls Control-  A policy on the use of cryptographic controls to secure information should be developed and enforced. Implementation Guidance-  The following should be considered when designing a cryptographic policy: A management guide to the use of cryptographic controls across the organization, including the general principles by which business  information  should be protected; Based on the risk assessment, the necessary level of security should be calculated taking into account the type, strength, and quality of the encryption algorithm necessary...

ISO 27001 Annex : A.9.4 System and Application Access Control

Image
ISO 27001 Annex : A.9.4 System and Application Access Control  Its objective is  to put a stop to unauthorized access to systems and applications. A.9.4.1 Information Access Restriction Control-  Access to information and application system functions should be limited in compliance with the policy on access control. Implementation Guidance-  Access controls  should be based on individual requirements for business applications and in compliance with a specified access control policy. In order to meet access restriction criteria, the following should be considered:- Provide menus for controlling access to application system functions; Controlling which data a particular user can access; Control  user access  permission, e.g. read, write, delete, and execute; Control of the access permission to other applications; Restrict the information contained in the outputs; Physical or logical access controls for sensitive applications, applicat...