Artigos

Steps for Implementing ISO 27001

In providing guidance on the planning and decision-making processes associated with ISO 27001 implementation, ISACA® Journal volume 4 author Charu Pelnekar, CISA, CISM, ACA, AICWA, BCOM, CISSP, CPA, MCSE, QSA, offered the following steps to implement ISO/IEC 27001:2005 Information technology—Security techniques—Information security management systems.

Requirements:

  1. Identify business objectives.
  2. Obtain management support.
  3. Select the proper scope of implementation.
  4. Define a method of risk assessment.
  5. Prepare an inventory of information assets to protect, and rank assets according to risk classification based on the risk assessment.
  6. Manage the risk, and create a risk treatment plan.
  7. Set up policies and procedures to control risk.
  8. Allocate resources, and train the staff.
  9. Monitor the implementation of the information security management system.
  10. Prepare for the certification audit.
  11. Conduct periodic reassessment audits.

Read Pelnekar’s full article, “Planning for and Implementing ISO 27001,” in the current issue of the ISACA Journal, in which you will also find additional coverage of timely and relevant issues affecting the ISACA® professional communities.

marcos

Professor, Embaixador e Comendador MSc. Marcos Assi, CCO, CRISC, ISFS – Sócio-Diretor da MASSI Consultoria e Treinamento Ltda – especializada em Governança Corporativa, Compliance, Gestão de Riscos, Controles Internos, Mapeamento de processos, Segurança da Informação e Auditoria Interna. Empresa especializada no atendimento de Cooperativas de Crédito e habilitado pelo SESCOOP no Brasil todo para consultoria e Treinamento. Mestre em Ciências Contábeis e Atuariais pela PUC-SP, Bacharel em Ciências Contábeis pela FMU, com Pós-Graduação em Auditoria Interna e Perícia pela FECAP, Certified Compliance Officer – CCO pelo GAFM, Certified in Risk and Information Systems Control – CRISC pelo ISACA e Information Security Foundation – ISFS pelo EXIN.