Posts

Showing posts with the label access

ISO 27001 Annex : A.15 Supplier Relationships

Image
  ISO 27001 Annex : A.15 Supplier Relationships in this article explaining Information Security in Supplier Relationships, and there policies . A.15.1  Information Security in Supplier Relationships It’s objective is  ensuring the security of assets accessible to suppliers of the organization. A.15.1.1  Information Security Policy for Supplier Relationships Control-  The supplier should be agreed with and documented  information security  requirements related to the risk mitigation of access by suppliers to organizational assets. “The company becomes more safe and happy if it has better Stakeholders.” Related Product :  ISO 27001 Lead Auditor Training And Certification ISMS Implementation Guidance –  In order to specifically address supplier access to information from the organization, the organization must identify and require security information controls in its policy. These checks should address the organization’s processing and procedure...

For a hacker, chaos isn’t a pit, Chaos is ladder

Image
  For a hacker, chaos isn’t a pit, Chaos is ladder this idea is explained during this article with the assistance of some hacker and their terms. “To better describe hacking, one needs to first understand hackers.”   Who may be a Hacker? A hacker is a private who uses computer, networking or other skills to beat a technical problem. The term hacker may ask anyone with technical skills, but it often refers to an individual who uses his or her abilities to realize unauthorized access to systems or networks so as to commit  crimes . A hacker may, for instance , steal information to harm people via fraud , damage or bring down systems and, often, hold those systems hostage to gather ransom. What does a hacker do? Computer  hackers  are unauthorized users who forced an entry computer systems so as to steal, change or destroy information, often by installing dangerous malware without your knowledge or consent. Their clever tactics and detailed technical knowledge help...

ISO 27001 Annex : A.13 Communications Security

Image
  ISO 27001 Annex : A.13 Communications Security in this article explain  A.13.1  Network Security Management,  A.13.1.1  Network Controls,  A.13.1.2  Security of Network Services,  A.13.1.3  Segregation in Networks. A.13.1  Network Security Management It’s objective is to ensure the security and supporting information processing facilities of the information in a network. A.13.1.1  Network Controls Control-  To protect  information in systems  and applications, networks should be managed and monitored. Implementation Guidance –  The monitoring of network  information security  and the security of connected networks from unauthorized access should be undertaken. The following things will in particular be taken into account: Networking  equipment management  responsibilities and procedures should be established; Network operational responsibility can, where necessary, be segregated from compute...

ISO 27001 Annex : A.12.7 Information Systems Audit Considerations

Image
  ISO 27001 Annex : A.12.7 Information Systems Audit Considerations  Its objective  is minimizing the impact on operating systems of audit activities. A.12.7.1  Information Systems Audit Controls Control-  The  audit   criteria and activities related to operating system verification should be carefully prepared and decided in order to reduce business process disturbance. Implementation Guidance –  It is necessary to follow the following guidance: audit standards for access to systems and data should be negotiated with appropriate management; Scope should be agreed and controlled on the technical audit tests; Audit processing should be restricted to read-only access to applications and data; Access, rather than read-only, should only be permitted for isolated copies of system files, which should be deleted when the audit is completed, or provided with adequate  security  where such files are needed to be held in accordance with the docume...

ISO 27001 Annex : A.11 Physical and Environmental Security

Image
ISO 27001 Annex : A.11 Physical and Environmental Security in this article explain Secure areas, Physical Security Perimeter and Physical Entry Controls.  A.11.1 Secure areas Its objective is to avoid unauthorized physical access, damage and interference with the  organization’s information  and information processing facilities. A.11.1.1 Physical Security Perimeter Control-  Security perimeters should be established in order to secure areas that contain either sensitive or confidential information and information processing facilities. Implementation Guidance-  When appropriate, for physical security perimeters, the following guidelines should be considered and implemented: Security perimeters should be established and the location and intensity of each perimeter should depend on the security requirements of the assets inside the perimeter and on the results of the  risk assessment ; The building or facility perimeters should be physicall...