Re: ISO 17799

From: Alessandro Bottonelli (a.bottonelli_at_axis-net.it)
Date: 11/24/05

  • Next message: Jeroen van Meeuwen: "FW: Tunelling RDP traffic over HTTP proxies."
    To: security-basics@securityfocus.com
    Date: Thu, 24 Nov 2005 23:46:14 +0100
    
    

    On Saturday 22 October 2005 09:45, siangmeng lim wrote:
    >
    > Can someone help me in guiding me how a ISO 17799 certification
    > process is carry out ?
    >
    To be rigorous, there's no such thing as an ISO 17799 certification,
    ISO 17799 being a "guideline" - you can certify vs. BS7799:2 which is
    the document with the "shall" (whereas the ISO doc replaces "shall"s
    with "should"s ...).

    > How should any organization approach this
    > task if they have an intention to have their IT systems,
    >
    BS7799 (or as of Oct 15 -- ISO 270001) does not certify "IT Systems"
    but rather organizations. It may sound like philosophy or semantics
    -- but it makes a difference!

    > various
    > depts in the organizations to have a certain level of control and
    > management of information ? Is there a difference in approaches and
    > deliverables if it is a private company vs a gov agency ?
    >
    Since I *do* this for a living... I may sound interested -- yet I
    honestly think you should hire an experienced professional for such a
    task. It may save time, effort, and money in the long run.

    My 2 Eurocents...

    -- 
    Alessandro Bottonelli,
    CISSP & BS7799 Lead Auditor
    Axis-Net
    Tel. +39 02 93595859
    Web. http://www.axis-net.it
    

  • Next message: Jeroen van Meeuwen: "FW: Tunelling RDP traffic over HTTP proxies."

    Relevant Pages

    • Re: CE compliance testing in the UK
      ... Of course it's fluff. ... DO you have the little certification sticker? ... When ISO first came out I was involved in getting the processes ... The result of the processes didn't have high quality ...
      (sci.electronics.design)
    • Re: Public disclosure of discovered vulnerabilities
      ... >> the education and management problems that have struck ... I personally haven't found that ISO ... ISO 9000 is just another irrelevant nonsolution much like certification ...
      (sci.crypt)
    • Re: SHOPFOX DEALER PLANER QUESTION
      ... ISO is not a set of standards as the advertising ... ISO certification has two benefits. ...
      (rec.woodworking)
    • ISO 13485, how to ?
      ... an ISO 13485:2003 certification. ... I already talked to a company that is responsible for the certification ... If anyone can forward me a link to a completed ISO 13485 documentation, ... The point is that I want to avoid any consulting fees. ...
      (sci.engr.electrical.compliance)
    • ISO 9000 was: Re: Public disclosure of discovered vulnerabilities
      ... The principal of ISO 9000 is what we want: ... ISO 9000 gives us a case no PHB ... Certification means a third party checks that we do ... Bids and contracts ...
      (sci.crypt)