Posts

Showing posts with the label ISO 27001 Training in Mumbai

ISO 27001 Annex : A.11.2 Equipment

Image
ISO 27001 Annex : A.11.2 Equipment Its objective is to avoid loss, damage, theft, or compromise of assets and disrupt the operations of the organization. A.11.2.1  Equipment Siting and Protection Control- To mitigate the risk of   environmental  hazards, risks, and unauthorized access, the equipment should be sited and secured. Implementation Guidance- To protect equipment, the following directives should be considered: In order to minimize unnecessary access in work areas, equipment should be sited; Information   processing facilities that handle sensitive information should be carefully positioned to reduce the risk of unauthorized persons viewing information during their use; In order to avoid unauthorized access, storage facilities should be secured; Objects requiring special protection should be protected to reduce the required level of overall protection; The   risk   of potential threats to the environment and physicality such as...

ISO 27001 Annex : A.9.4.4 Use of Privileged Utility Programs & A.9.4.5 Access Control to Program Source Code

Image
In this article ISO 27001 Annex : A.9.4.4 Use of Privileged Utility Programs & A.9.4.5 Access Control to Program Source Code this two topics are explain. A.9.4.4 Use of Privileged Utility Programs Control-  The use of utility programs that could bypass system and application controls should  be limited and tightly controlled. Implementation Guidance-  The following guidelines should be taken into account when using utility programs that could override system and application controls: the use of procedures for identification, authentication, and authorization of utility programs; Segregation of the utility programs from software applications; Limiting the availability of utility services to the minimum practicable number of reliable,  authorized users  ( refer to 9.2.3 ); Approval for the ad hoc use of utility programs; Limiting the availability of utilities, e.g. for the time of the approved amendment; Logging the use of utility programs; ...

ISO 27001 Annex : A.9.2 User Access Management

Image
ISO 27001 Annex : A.9.2 User Access Management  Its  objective is to  ensure approved user access and avoid unauthorized access to systems and facilities. A.9.2.1 User registration and de-registration Control-  In order to allow the assignment of access rights, a systematic process of user  registration and de-registration should be enforced. Implementation guidance-  The process to manage user IDs should include: Use unique user IDs to encourage users to be connected to and hold accountable for their actions; use of shared IDs should only be permitted where they are required for business or operational purposes and should be authorized and documented. Immediately disable or delete user IDs of people that have left the  organization . Identifying and deleting or disabling redundant user IDs on a periodically Making sure that other users do not receive redundant UIs. Related Product :  ISO 27001 Lead Auditor Training And Certific...

ISO 27001 Annex : A.9.1.2 Access to Networks and Network Services

Image
Control-  ISO 27001 Annex : A.9.1.2 Access to Networks and Network Services Only network and network facilities which have expressly been approved for use will be made available to users. Implementation Guidance-  A policy on the use of networks and network policy should be developed. Following points should be covered in this policy: networks and network infrastructure to which access is permitted; Authorization procedures for determining who is permitted to access which networks and Networking services; Management  processes and policies for securing access to network interfaces and network services; the medium for networking and network services (for example, using VPN or wireless network); Access to various network services requires user authentication; Network service usage  monitoring . The network services policy should comply with the access control policy of the organization. Related Product :  ISO 27001 Lead Auditor Training And...