Posts

Showing posts with the label Integrity and Availability

ISO 27001 Annex : A.14.1.2 Securing Application Services on Public Networks

Image
  Control-  ISO 27001 Annex : A.14.1.2 Securing Application Services on Public Networks  Information about application services which pass through public networks should be protected against fraudulent activities, contract disputes, unauthorized disclosure, and modification. Implementation Guidance –  Information security requirements will include the following for application services that cross public networks: Each party requires a level of trust in the identity claimed by each other, for example, through authentication; Authorizations  for those who may authorize the content of key transnational documents, issue or sign them; Ensure that  communication  parties are fully aware of their service provision or usage authorizations; Determination and compliance with the conditions of  confidentiality, integrity , proof that key documents and contracts, for instance, related to contracts and tendering process, have been dispatched and received; The ...

ISO 27001 Annex : A.8.2 Information Classification

Image
ISO 27001 Annex : A.8.2 Information Classification  Its objective is  To ensure that the information is properly secured, in accordance with its significance to the organization. A.8.2.1 Classification of Information Control-  Information should be classification the basis of their legal provisions, criticality, and  vulnerability  to unwanted release or alteration Implementation Guidance-  Classifications and associated  information security  measures will also include regulatory standards, which take into account market demands for information sharing or restriction. Assets other than information may also be classified according to the information classification stored, processed, otherwise handled or protected by the asset. Information asset owners would be responsible for their classification. The classification system will include classification standards, as well as classification analysis guidelines over time. The level of sec...