Posts

Showing posts with the label authorization

ISO 27001 Annex : A.18.1.3, A.18.1.4 and A.18.1.5

Image
  In this article explain ISO 27001 Annex : A.18.1.3 Protection of Records, A.18.1.4 Privacy and Protection of Personally Identifiable Information and A.18.1.5 Regulation of   Cryptographic Controls   this contols. A.18.1.3 Protection of Records Control-  ISO 27001 Annex : A.18.1.3 Protection of Records  Records shall, in accordance with the provisions to legislative, regulatory, contractual, and business requirements, to protect from loss, destruction, falsification, and unauthorized access and unauthorized release. Implementation Guidance-  The related classification based on the  organization’s  classification scheme is to be taken into account when determining whether to secure relevant organizational documents. Categorized records in the following types of records, such as accounting records, database records, transaction records, audit logs, and operating procedures, should include details on retention periods and the type of media permitted...

ISO 27001 Annex : A.14.3 Test data

Image
ISO 27001 Annex : A.14.3  Test data its objective is to ensure that data used for research are secured. A.14.3.1  Protection of test data Control –  Careful collection, security, and review of test data should be performed. Implementation Guidance –  It should be avoided the use of operational information containing personal information or any other confidential  information  for test purposes. Where personal information or otherwise confidential information for testing purposes is used, all sensitive information and content should be protected either by deletion or modification. When used for testing purposes, the following guidelines should be used for the protection of operational data: The  access management  protocols applicable to the running application systems should also refer to the  application control  systems; Every time operational information is copied to the test setting, separate authorization should be granted; Operatio...

ISO 27001 Annex : A.14.2 Security in Development and Support Processes

Image
  ISO 27001 Annex : A.14.2  Security in Development and Support Processes  It’s objective is  ensuring the creation and implementation of  information security  in the information system development process. A.14.2.1  Secure Development Policy Control-  Regulations for software and system development should be laid down and applied to organizational developments. Implementation Guidance –  Secure development includes a safe infrastructure, architecture, software, and system to be developed. The following considerations should be taken into account in a stable technology policy: Environmental development security; security guidelines for the life cycle of software development: security in the methodology for software development; Secure guidelines on code for each language of programming used; Design-phase protection requirements; Security control   points within the milestones of the project; secure repositories; Version control security...

ISO 27001 Annex : A.13.2 Information Transfer

Image
ISO 27001 Annex : A.13.2  Information Transfer  Its objective  is to maintain the security of information transferred to any external entity and within the organization. A.13.2.1  Information Transfer Policies and Procedures Control-   In order to protect the transferees by using all types of communication facilities, official transfer policies, procedures and controls should be developed. Implementation guidance –  The following items should be addressed in the procedures and controls required to use communications facilities to transmit information: Procedures to prevent interception, copying, altering, misrouting or destruction of transmitted information; Procedures to detect and protect malware from electronic communications which can be transmitted; Procedures for the protection of communicated electronically sensitive information in the form of an attachment; Guidelines or rules specifying an appropriate usage of communication facilities ( refer to 8....

ISO 27001 Annex : A.11 Physical and Environmental Security

Image
ISO 27001 Annex : A.11 Physical and Environmental Security in this article explain Secure areas, Physical Security Perimeter and Physical Entry Controls.  A.11.1 Secure areas Its objective is to avoid unauthorized physical access, damage and interference with the  organization’s information  and information processing facilities. A.11.1.1 Physical Security Perimeter Control-  Security perimeters should be established in order to secure areas that contain either sensitive or confidential information and information processing facilities. Implementation Guidance-  When appropriate, for physical security perimeters, the following guidelines should be considered and implemented: Security perimeters should be established and the location and intensity of each perimeter should depend on the security requirements of the assets inside the perimeter and on the results of the  risk assessment ; The building or facility perimeters should be physicall...