Security Policy: Difference between revisions
Jump to navigation
Jump to search
| Line 79: | Line 79: | ||
=== Actions to address risks and opportunities=== | === Actions to address risks and opportunities=== | ||
==== General==== | ==== General==== | ||
When planning for the information security management system, the organization shall consider the issues referred to [[https://wiki.officience.com/Security_Policy#Understanding_the_organization_and_its_context|]] and the requirements referred to in [[https://wiki.officience.com/Security_Policy#Understanding_the_needs_and_expectations_of_interested_parties]] and determine the risks and opportunities that need to be addressed to: | When planning for the information security management system, the organization shall consider the issues referred to [[https://wiki.officience.com/Security_Policy#Understanding_the_organization_and_its_context|]] and the requirements referred to in [[https://wiki.officience.com/Security_Policy#Understanding_the_needs_and_expectations_of_interested_parties]] and determine the risks and opportunities that need to be addressed to: | ||
* ensure the information security management system can achieve its intended outcome(s); | |||
* prevent, or reduce, undesired effects; and | |||
* achieve continual improvement. | |||
The organization shall plan: | The organization shall plan: | ||
* actions to address these risks and opportunities; and | |||
* how to: (a) integrate and implement the actions into its information security management system processes; and | |||
(b) evaluate the effectiveness of these actions. | |||
====Information security risk assessment==== | ====Information security risk assessment==== | ||
| Line 94: | Line 96: | ||
The organization shall define and apply an information security risk assessment process that: | The organization shall define and apply an information security risk assessment process that: | ||
* Establishes and maintains information security risk criteria that include: | |||
(a) the risk acceptance criteria; and | |||
(b) criteria for performing information security risk assessments; | |||
* Ensures that repeated information security risk assessments produce consistent, valid and comparable results; | |||
* Identifies the information security risks: | |||
(a) apply the information security risk assessment process to identify risks associated with the loss of confidentiality, integrity and availability for information within the scope of the information security management system; and | |||
(b) identify the risk owners; | |||
* Analyses the information security risks: | |||
(a) assess the potential consequences that would result if the risks identified were to materialize; | |||
(b) assess the realistic likelihood of the occurrence of the risks identified; and | |||
(c)determine the levels of risk; | |||
* Evaluates the information security risks: | |||
(a) compare the results of risk analysis with the risk criteria established; and | |||
(b) prioritize the analysed risks for risk treatment. | |||
The organization shall retain documented information about the information security risk assessment process. | The organization shall retain documented information about the information security risk assessment process. | ||
| Line 105: | Line 116: | ||
The organization shall define and apply an information security risk treatment process to: | The organization shall define and apply an information security risk treatment process to: | ||
# | # Select appropriate information security risk treatment options, taking account of the risk assessment results; | ||
assessment results; | |||
# | # Determine all controls that are necessary to implement the information security risk treatment option(s) chosen; | ||
option(s) chosen; | |||
<small>NOTE Organizations can design controls as required, or identify them from any source. </small> | <small>NOTE Organizations can design controls as required, or identify them from any source. </small> | ||
# | # Compare the controls determined above with those in Annex A of ISO/IEC 27001:2013 and verify that no necessary controls have been omitted; | ||
<small>NOTE 1 Annex A contains a comprehensive list of control objectives and controls. Users of this International Standard are directed to Annex A to ensure that no necessary controls are overlooked. | <small>NOTE 1 Annex A contains a comprehensive list of control objectives and controls. Users of this International Standard are directed to Annex A to ensure that no necessary controls are overlooked. | ||
| Line 119: | Line 128: | ||
NOTE 2 Control objectives are implicitly included in the controls chosen. The control objectives and controls listed in Annex A are not exhaustive and additional control objectives and controls may be needed.</small> | NOTE 2 Control objectives are implicitly included in the controls chosen. The control objectives and controls listed in Annex A are not exhaustive and additional control objectives and controls may be needed.</small> | ||
# | # Produce a Statement of Applicability that contains the necessary controls above and justification for inclusions, whether they are implemented or not, and the justification for exclusions of controls from Annex A; | ||
# | # Formulate an information security risk treatment plan; and | ||
# | # Obtain risk owners’ approval of the information security risk treatment plan and acceptance of the residual information security risks. | ||
The organization shall retain documented information about the information security risk treatment process. | The organization shall retain documented information about the information security risk treatment process. | ||
| Line 129: | Line 138: | ||
<small>NOTE The information security risk assessment and treatment process in this International Standard aligns with the principles and generic guidelines provided in ISO 31000[5]. </small> | <small>NOTE The information security risk assessment and treatment process in this International Standard aligns with the principles and generic guidelines provided in ISO 31000[5]. </small> | ||
=== | === Information security objectives and planning to achieve them=== | ||
The organization shall establish information security objectives at relevant functions and levels. | The organization shall establish information security objectives at relevant functions and levels. | ||
The information security objectives shall: | The information security objectives shall: | ||
* be consistent with the information security policy; | |||
* be measurable (if practicable); | |||
* take into account applicable information security requirements, and results from risk assessment and risk treatment; | |||
* be communicated; and | |||
* be updated as appropriate. | |||
The organization shall retain documented information on the information security objectives. When planning how to achieve its information security objectives, the organization shall determine: | The organization shall retain documented information on the information security objectives. When planning how to achieve its information security objectives, the organization shall determine: | ||
* what will be done; | |||
* what resources will be required; | |||
* who will be responsible; | |||
* when it will be completed; and | |||
* how the results will be evaluated. | |||
==Support== | ==Support== | ||