Skip to main content

Certikit a guide to implementing the iso iec 27001 standard

Page 34

A Guide to Implementing the ISO/IEC 27001 Standard

   

Information Security Policy for Supplier Relationships Supplier Information Security Agreement Supplier Due Diligence Assessment Procedure Supplier Due Diligence Assessment

A chain is only as strong as its weakest link and if you share sensitive information with your suppliers then the standard requires you to take adequate measures to ensure that they protect it as well as you do. This may be achieved via a combination of second party audits (see Supplier Information Security Evaluation Process), contractual agreements and strong access control over remote links to and from suppliers. Much of this will depend on how important a customer you are to your suppliers; small organizations who are customers of large suppliers may have less influence over contractual terms and the security controls in place. This should be considered when deciding which supplier to choose in any particular situation.

3.12 A.16 Information security incident management

Relevant Toolkit documents  

Information Security Event Assessment Procedure Information Security Incident Response Procedure

It’s easy to ignore the event management requirements of the standard and focus on incidents, but doing this risks falling foul of the auditor. In your information security environment you will most likely be bombarded with things that happen on a daily basis that may or may not be incidents and being able to work out the difference quickly will be key. Ensure you have a clear approach to assessing events to decide whether or not you’ve been breached as crying wolf too often will get you a bad reputation. Information security incident management is becoming increasingly important as organizations realize that preventing all breaches is virtually impossible. If you have an existing IT incident management process (usually provided via an IT service or help desk) it may make sense to enhance this to cover information security incidents rather than have a separate process running side by side. For major breaches with potentially significant consequences for the reputation of the organization the best approach is to be prepared and well drilled in your response. This situation has a lot in common with a business continuity event and should be managed in much the same way, with senior management involvement from the outset.

V7 Copyright CertiKit 2016

Page 33


Turn static files into dynamic content formats.

Create a flipbook
Certikit a guide to implementing the iso iec 27001 standard by CertiKit Limited - Issuu