Posts

Showing posts with the label agreements

ISO 27001 Annex : A.15.1.2 Addressing Security Within Supplier Agreements & A.15.1.3 Information and Communication Technology Supply Chain

Image
  In this article explain ISO 27001 Annex : A.15.1.2 Addressing Security Within Supplier Agreements & A.15.1.3 Information and Communication Technology Supply Chain this controls. A.15.1.2  Addressing Security Within Supplier Agreements Control-  Any suppliers that view, process, store, communicate or provide IT infrastructure component  information for the organization  should be defined and agreed with all applicable information security requirements. Implementation Guidance-  Supplier agreements should be defined and recorded so that the organization and the supplier do not misinterpret the obligations of the two parties to meet the applicable  information security   requirements. Related Product :  ISO 27001 Lead Auditor Training And Certification ISMS To meet the information security requirements identified, the following points should be considered for inclusion in the agreements: Description of information and methods of supply and...

ISO 27001 Annex : A.13.2.3 Electronic Messaging & A.13.2.4 Confidentiality or Non-Disclosure Agreements

Image
In this article explain ISO 27001 Annex : A.13.2.3 Electronic Messaging & A.13.2.4 Confidentiality or Non-Disclosure Agreements . A.13.2.3  Electronic Messaging Control-  Electronic messaging information should be adequately protected. Implementation Guidance –   The following should include information security aspects for electronic messages: Protecting messages against unauthorized access, change or denial of services in line with the organization’s  classification  scheme; ensure that the message is correctly addressed and transported; Service reliability and availability; Legal considerations, such as electronic signature requirements; Approval before using external public authorities, such as instant messaging,  social networking  or sharing of files; Stronger standards of publicly accessible network authentication  access management . Other Information –  There are various kinds of messages, such as e-mail systems, an exchange of e...

ISO 27001 Annex : A.13.2 Information Transfer

Image
ISO 27001 Annex : A.13.2  Information Transfer  Its objective  is to maintain the security of information transferred to any external entity and within the organization. A.13.2.1  Information Transfer Policies and Procedures Control-   In order to protect the transferees by using all types of communication facilities, official transfer policies, procedures and controls should be developed. Implementation guidance –  The following items should be addressed in the procedures and controls required to use communications facilities to transmit information: Procedures to prevent interception, copying, altering, misrouting or destruction of transmitted information; Procedures to detect and protect malware from electronic communications which can be transmitted; Procedures for the protection of communicated electronically sensitive information in the form of an attachment; Guidelines or rules specifying an appropriate usage of communication facilities ( refer to 8....