Posts

Showing posts with the label CQI | IRCA ISO 27001 Lead Auditor

ISO 27001 Annex : A.12.2 Protection from Malware

Image
  ISO 27001 Annex : A.12.2 Protection from Malware  It’s objective is  ensuring that malware protection is provided to information and information processing facilities. A.12.2.1  Controls Against Malware Control-  In combination with appropriate user awareness, the detection, prevention, and recovery controls to protect against malware should be implemented. Implementation guidance Malware protection should be supported by malware detection and repair software, awareness of the safety of information, and adequate system access and  management reviews  on changes. The guidance should be considered as follows: a create formal policy barring the use of unauthorized software;   Implementation of controls preventing or detecting the use of unauthorized software; Implement controls which avoid or detect the use of malicious websites known or suspected (e.g. blacklisting); Create a structured  risk management   policy, which indicates wha...

ISO 27001 Annex : A.11.2.7 Secure Disposal or Re-use of Equipment, A.11.2.8 Unattended User Equipment & A.11.2.9 Clear Desk and Clear Screen Policy

Image
  In this article explain ISO 27001 Annex : A.11.2.7  Secure Disposal or Re-use of Equipment, A.11.2.8 Unattended User Equipment & A.11.2.9 Clear Desk and Clear Screen Policy A.11.2.7  Secure Disposal or Re-use of Equipment Control-  To avoid the removal or overriding of sensitive data and software by the disposal or reuse of any device containing storage medium, all devices must be reviewed. Implementation Guidance-  Equipment should be tested to ensure that the storage media is contained or not until disposal or re-use. In order to make original information inaccessible instead of using the standard delete or a software functionality, the storage media with confidential or copyrighted information should physically be destroyed or information destroyed, deleted, or overwritten using techniques. Other information-  Determining whether the items should be physically destroyed rather than sent to repair or discard damaged  equipment containing  ...

ISO 27001 Annex : A.7.3 Termination and Change of Employment

Image
ISO 27001 Annex : A.7.3 Termination and Change of Employment  Its objective is to  safeguard the interests of the  organization  as part of the adjustment or termination of employment. A.7.3.1 Termination or change of Employment Responsibilities Control-  Responsibility and  information security  requirements that continue to be valid following  termination or change of employment must be defined, communicated to, and implemented by the employee or contractor. Implementation Guidance-  Communication of termination duties may include on-going information security requirements and legal responsibilities and, as applicable, the duties found in the confidentiality arrangement and the terms and conditions of employment to be maintained for a specified time following the termination of the job of the employee or contractor. Responsibilities  and duties still valid after termination must be included in the terms and conditions of e...