SlideShare una empresa de Scribd logo
1 de 31
ISO 27001
    The CEO Guide
to implement ISO 27001
ISO 27001
     ISO 27002 ISO 27001


ISO 27001


ISO 9001
Information can be
                                      Stolen
Entered
 Created




                                          Lost
Stored
           Processed   Destroyed   Corrupted
Information
   Assets
Information

              •
              •
              •
              •
              •
What is Information?

   “Information is an asset which, like other important
    business assets, has value to an organization and
      consequently needs to be suitably protected.”




Ref: ISO/IEC 17799:2005
Criteria of Information Security.




                Confidentiality


                  Information
                    Security

        Availability         Integrity
People                Processes




         Technology
Processes




Technology



                 People
Information           Security          Management system




Tangible assets     Confidentiality   People, Processes , Technology
Intangible assets   Integrity            Plan | Do | Check | Act
                     Availability



 ISO 27002, Code of Practice For           ISO 27001, Information
Information Security Management             Security Management
                                           Systems – Requirement

  These standards are accepted as industry best practices
ISO 27001
ISO 27001
ISO 27001




       Statement of
                      applicability
ISO 27001




       Statement of
                      applicability
Military      Commercial
Top Secret.     Confidential.
Secret.         Private.
Confidential.   Sensitive.
Sensitive.      Public.
Unclassified.
ISO 27001




       Statement of
                      applicability
ISO 27001
ISO 27002 ISO 27001
   ISO 27002          ISO 27001


Control



          ISO 27001
Technical Proposal
Implementation Methodology
        Training Process
          Project Documents
ISO 27001
ISO 27001
ISO 27001
ISO 9001




           ISO 27001
Conclusion

      ISO 27001
Questions & Answers
• IT GOVERNANCE, A Manager's Guide to
  Data Security and ISO 27001/ISO 27002, 4th
  edition, Alan Calder & Steve Watkins.
• Effectively Managing Information Security
  Risk, A guide for executives, Citadel
  Information Group, Inc. , January, 2007
• http://iso27001standard.com.

Más contenido relacionado

La actualidad más candente

Transitioning to iso 27001 2013
Transitioning to iso 27001 2013Transitioning to iso 27001 2013
Transitioning to iso 27001 2013
SAIGlobalAssurance
 

La actualidad más candente (20)

NQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation Guide
 
ISO 27001 - three years of lessons learned
ISO 27001 - three years of lessons learnedISO 27001 - three years of lessons learned
ISO 27001 - three years of lessons learned
 
ISO 27001 - Information Security Management System
ISO 27001 - Information Security Management SystemISO 27001 - Information Security Management System
ISO 27001 - Information Security Management System
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
ISO 27001 Certification: An All-Access Pass
ISO 27001 Certification: An All-Access PassISO 27001 Certification: An All-Access Pass
ISO 27001 Certification: An All-Access Pass
 
ISO 27001 Training | ISO 27001 Implementation
ISO 27001 Training | ISO 27001 ImplementationISO 27001 Training | ISO 27001 Implementation
ISO 27001 Training | ISO 27001 Implementation
 
ISO 27001:2013 - A transition guide
ISO 27001:2013 - A transition guideISO 27001:2013 - A transition guide
ISO 27001:2013 - A transition guide
 
Basic introduction to iso27001
Basic introduction to iso27001Basic introduction to iso27001
Basic introduction to iso27001
 
NQA Your Risk Assurance Partner
NQA Your Risk Assurance PartnerNQA Your Risk Assurance Partner
NQA Your Risk Assurance Partner
 
ISO 27001 Benefits
ISO 27001 BenefitsISO 27001 Benefits
ISO 27001 Benefits
 
ISO/IEC 27001:2013 An Overview
ISO/IEC 27001:2013  An Overview ISO/IEC 27001:2013  An Overview
ISO/IEC 27001:2013 An Overview
 
ISO 27001 control A17 (Continuity on Information Security), and ISO 22301: co...
ISO 27001 control A17 (Continuity on Information Security), and ISO 22301: co...ISO 27001 control A17 (Continuity on Information Security), and ISO 22301: co...
ISO 27001 control A17 (Continuity on Information Security), and ISO 22301: co...
 
All you wanted to know about iso 27000
All you wanted to know about iso 27000All you wanted to know about iso 27000
All you wanted to know about iso 27000
 
Iso 27001 awareness
Iso 27001 awarenessIso 27001 awareness
Iso 27001 awareness
 
Iso27001- Nashwan Mustafa
Iso27001- Nashwan MustafaIso27001- Nashwan Mustafa
Iso27001- Nashwan Mustafa
 
ISO 27001:2013 - Changes
ISO 27001:2013 -  ChangesISO 27001:2013 -  Changes
ISO 27001:2013 - Changes
 
Guide on ISO 27001 Controls
Guide on ISO 27001 ControlsGuide on ISO 27001 Controls
Guide on ISO 27001 Controls
 
Implementing ISO27001 2013
Implementing ISO27001 2013Implementing ISO27001 2013
Implementing ISO27001 2013
 
Transitioning to iso 27001 2013
Transitioning to iso 27001 2013Transitioning to iso 27001 2013
Transitioning to iso 27001 2013
 
Why ISO-27001 is a better choice?
Why ISO-27001 is a better choice? Why ISO-27001 is a better choice?
Why ISO-27001 is a better choice?
 

Destacado

Information Security Management Systems(ISMS) By Dr Wafula
Information Security Management Systems(ISMS) By Dr  WafulaInformation Security Management Systems(ISMS) By Dr  Wafula
Information Security Management Systems(ISMS) By Dr Wafula
Discover JKUAT
 
Implementing a Security Framework based on ISO/IEC 27002
Implementing a Security Framework based on ISO/IEC 27002Implementing a Security Framework based on ISO/IEC 27002
Implementing a Security Framework based on ISO/IEC 27002
pgpmikey
 
المهندس جـلال الطبـطبـائي احصائيات شهادات الجودة Iso
المهندس جـلال الطبـطبـائي        احصائيات شهادات الجودة Isoالمهندس جـلال الطبـطبـائي        احصائيات شهادات الجودة Iso
المهندس جـلال الطبـطبـائي احصائيات شهادات الجودة Iso
qualitysummit
 
الجزء الثالث والاخير ملخص مادة الادارة
الجزء الثالث والاخير ملخص مادة الادارة الجزء الثالث والاخير ملخص مادة الادارة
الجزء الثالث والاخير ملخص مادة الادارة
Fida Kadun
 
تعريف الادارة جزء اخير
تعريف الادارة جزء اخيرتعريف الادارة جزء اخير
تعريف الادارة جزء اخير
Fida Kadun
 
محمد العتي تطبيق الجودة في الجهات الحكومية - الهيئة العامة للغذاء وا...
محمد العتي          تطبيق الجودة في الجهات الحكومية - الهيئة العامة للغذاء وا...محمد العتي          تطبيق الجودة في الجهات الحكومية - الهيئة العامة للغذاء وا...
محمد العتي تطبيق الجودة في الجهات الحكومية - الهيئة العامة للغذاء وا...
qualitysummit
 
Dr. amel farrag lean six sigma in healthcare
Dr. amel farrag   lean six sigma in healthcareDr. amel farrag   lean six sigma in healthcare
Dr. amel farrag lean six sigma in healthcare
qualitysummit
 

Destacado (20)

Mapa mental iso 27002
Mapa mental iso 27002Mapa mental iso 27002
Mapa mental iso 27002
 
Information Security Management Systems(ISMS) By Dr Wafula
Information Security Management Systems(ISMS) By Dr  WafulaInformation Security Management Systems(ISMS) By Dr  Wafula
Information Security Management Systems(ISMS) By Dr Wafula
 
Implementing a Security Framework based on ISO/IEC 27002
Implementing a Security Framework based on ISO/IEC 27002Implementing a Security Framework based on ISO/IEC 27002
Implementing a Security Framework based on ISO/IEC 27002
 
Iso 27001 isms presentation
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentation
 
ISO 27002 Foundation ISFS
ISO 27002 Foundation ISFSISO 27002 Foundation ISFS
ISO 27002 Foundation ISFS
 
ISO 27002 2013 Atualizações / mudanças
ISO 27002 2013 Atualizações / mudanças ISO 27002 2013 Atualizações / mudanças
ISO 27002 2013 Atualizações / mudanças
 
المهندس جـلال الطبـطبـائي احصائيات شهادات الجودة Iso
المهندس جـلال الطبـطبـائي        احصائيات شهادات الجودة Isoالمهندس جـلال الطبـطبـائي        احصائيات شهادات الجودة Iso
المهندس جـلال الطبـطبـائي احصائيات شهادات الجودة Iso
 
الادارة ج2
الادارة ج2الادارة ج2
الادارة ج2
 
ادارة
ادارةادارة
ادارة
 
الجزء الثالث والاخير ملخص مادة الادارة
الجزء الثالث والاخير ملخص مادة الادارة الجزء الثالث والاخير ملخص مادة الادارة
الجزء الثالث والاخير ملخص مادة الادارة
 
تعريف الادارة جزء اخير
تعريف الادارة جزء اخيرتعريف الادارة جزء اخير
تعريف الادارة جزء اخير
 
Managing Leadership Talent
Managing Leadership TalentManaging Leadership Talent
Managing Leadership Talent
 
DalilakLiltraqi
DalilakLiltraqiDalilakLiltraqi
DalilakLiltraqi
 
محمد العتي تطبيق الجودة في الجهات الحكومية - الهيئة العامة للغذاء وا...
محمد العتي          تطبيق الجودة في الجهات الحكومية - الهيئة العامة للغذاء وا...محمد العتي          تطبيق الجودة في الجهات الحكومية - الهيئة العامة للغذاء وا...
محمد العتي تطبيق الجودة في الجهات الحكومية - الهيئة العامة للغذاء وا...
 
Fast Forward Development program in Coca-Cola HBC
Fast Forward Development program in Coca-Cola HBCFast Forward Development program in Coca-Cola HBC
Fast Forward Development program in Coca-Cola HBC
 
مهارات التخطيط
مهارات التخطيطمهارات التخطيط
مهارات التخطيط
 
Management
ManagementManagement
Management
 
Information security management system (isms) overview
Information security management system (isms) overviewInformation security management system (isms) overview
Information security management system (isms) overview
 
Dr. amel farrag lean six sigma in healthcare
Dr. amel farrag   lean six sigma in healthcareDr. amel farrag   lean six sigma in healthcare
Dr. amel farrag lean six sigma in healthcare
 
قيادة فرق العمل
قيادة فرق العمل قيادة فرق العمل
قيادة فرق العمل
 

Similar a Mr. ahmed obaid the ceo guide to implement iso 27001

ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
PECB
 
Iso27001 Isaca Seminar (23 May 08)
Iso27001  Isaca Seminar (23 May 08)Iso27001  Isaca Seminar (23 May 08)
Iso27001 Isaca Seminar (23 May 08)
samsontamwaiho
 

Similar a Mr. ahmed obaid the ceo guide to implement iso 27001 (20)

Overview of ISO 27001 ISMS
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMS
 
Iso 27001 isms
Iso 27001 ismsIso 27001 isms
Iso 27001 isms
 
Iso 27001 isms - white paper
Iso 27001   isms -   white paperIso 27001   isms -   white paper
Iso 27001 isms - white paper
 
ISO 27001 Certification in Libya
ISO 27001 Certification in Libya ISO 27001 Certification in Libya
ISO 27001 Certification in Libya
 
Information Security Management System ISO/IEC 27001:2005
Information Security Management System ISO/IEC 27001:2005Information Security Management System ISO/IEC 27001:2005
Information Security Management System ISO/IEC 27001:2005
 
Tata Kelola Keamanan Informasi
Tata Kelola Keamanan InformasiTata Kelola Keamanan Informasi
Tata Kelola Keamanan Informasi
 
2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdf
 
ISO 27001 Certification in Denmark
ISO 27001 Certification in DenmarkISO 27001 Certification in Denmark
ISO 27001 Certification in Denmark
 
Know more about exin unique information security program
Know more about exin unique information security programKnow more about exin unique information security program
Know more about exin unique information security program
 
ISO 27001- 2022 ISMS Documents - Editable Format
ISO 27001- 2022 ISMS Documents - Editable FormatISO 27001- 2022 ISMS Documents - Editable Format
ISO 27001- 2022 ISMS Documents - Editable Format
 
Friday Forum ISO 27001: 2013
Friday Forum ISO 27001: 2013Friday Forum ISO 27001: 2013
Friday Forum ISO 27001: 2013
 
STAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 CertifiedSTAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 Certified
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risks
 
Information security
Information securityInformation security
Information security
 
we45 ISO-27001 Case Study
we45 ISO-27001 Case Studywe45 ISO-27001 Case Study
we45 ISO-27001 Case Study
 
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27032: How do they map?
 
ISO 27001 Certification in libya.pdf
ISO 27001 Certification in libya.pdfISO 27001 Certification in libya.pdf
ISO 27001 Certification in libya.pdf
 
ISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdfISO 27001 2002 Update Webinar.pdf
ISO 27001 2002 Update Webinar.pdf
 
ISMS User_Awareness Training.pptx
ISMS User_Awareness Training.pptxISMS User_Awareness Training.pptx
ISMS User_Awareness Training.pptx
 
Iso27001 Isaca Seminar (23 May 08)
Iso27001  Isaca Seminar (23 May 08)Iso27001  Isaca Seminar (23 May 08)
Iso27001 Isaca Seminar (23 May 08)
 

Más de qualitysummit

د. محمد أشكناني إدارة الجودة الشاملة في الجهات الحكومية وتطبيق آليات ال...
د. محمد أشكناني       إدارة الجودة الشاملة في الجهات الحكومية وتطبيق آليات ال...د. محمد أشكناني       إدارة الجودة الشاملة في الجهات الحكومية وتطبيق آليات ال...
د. محمد أشكناني إدارة الجودة الشاملة في الجهات الحكومية وتطبيق آليات ال...
qualitysummit
 
Mr. yasser mostafa kaizen the key to japan’s competitive success
Mr. yasser mostafa   kaizen the key to japan’s competitive successMr. yasser mostafa   kaizen the key to japan’s competitive success
Mr. yasser mostafa kaizen the key to japan’s competitive success
qualitysummit
 
Mr. stephen geach a case for quality
Mr. stephen geach   a case for qualityMr. stephen geach   a case for quality
Mr. stephen geach a case for quality
qualitysummit
 
Mr. stephen geach a case for quality (2)
Mr. stephen geach   a case for quality (2)Mr. stephen geach   a case for quality (2)
Mr. stephen geach a case for quality (2)
qualitysummit
 
Mr. mohammed rabei 7 keys to successfully implement improvement projects th...
Mr. mohammed rabei   7 keys to successfully implement improvement projects th...Mr. mohammed rabei   7 keys to successfully implement improvement projects th...
Mr. mohammed rabei 7 keys to successfully implement improvement projects th...
qualitysummit
 
Mr. mazen al amirah - quality is a lifestyle
Mr. mazen al  amirah - quality is a lifestyleMr. mazen al  amirah - quality is a lifestyle
Mr. mazen al amirah - quality is a lifestyle
qualitysummit
 
Mr. aref the “100 million dollars” cultural transformation initiative
Mr. aref   the “100 million dollars” cultural transformation initiativeMr. aref   the “100 million dollars” cultural transformation initiative
Mr. aref the “100 million dollars” cultural transformation initiative
qualitysummit
 
Dr. bibi al ajmi - quality and knowledge management what you have to do with it
Dr. bibi al  ajmi - quality and knowledge management what you have to do with itDr. bibi al  ajmi - quality and knowledge management what you have to do with it
Dr. bibi al ajmi - quality and knowledge management what you have to do with it
qualitysummit
 
Dr. abdul hai بطاقات الأداء المتوازنالأداء الاستراتيجي واستمرارية التطوير
Dr. abdul hai   بطاقات الأداء المتوازنالأداء الاستراتيجي واستمرارية التطويرDr. abdul hai   بطاقات الأداء المتوازنالأداء الاستراتيجي واستمرارية التطوير
Dr. abdul hai بطاقات الأداء المتوازنالأداء الاستراتيجي واستمرارية التطوير
qualitysummit
 
Mr. terje tonsberg tqm in service organizations
Mr. terje tonsberg   tqm in service organizationsMr. terje tonsberg   tqm in service organizations
Mr. terje tonsberg tqm in service organizations
qualitysummit
 

Más de qualitysummit (10)

د. محمد أشكناني إدارة الجودة الشاملة في الجهات الحكومية وتطبيق آليات ال...
د. محمد أشكناني       إدارة الجودة الشاملة في الجهات الحكومية وتطبيق آليات ال...د. محمد أشكناني       إدارة الجودة الشاملة في الجهات الحكومية وتطبيق آليات ال...
د. محمد أشكناني إدارة الجودة الشاملة في الجهات الحكومية وتطبيق آليات ال...
 
Mr. yasser mostafa kaizen the key to japan’s competitive success
Mr. yasser mostafa   kaizen the key to japan’s competitive successMr. yasser mostafa   kaizen the key to japan’s competitive success
Mr. yasser mostafa kaizen the key to japan’s competitive success
 
Mr. stephen geach a case for quality
Mr. stephen geach   a case for qualityMr. stephen geach   a case for quality
Mr. stephen geach a case for quality
 
Mr. stephen geach a case for quality (2)
Mr. stephen geach   a case for quality (2)Mr. stephen geach   a case for quality (2)
Mr. stephen geach a case for quality (2)
 
Mr. mohammed rabei 7 keys to successfully implement improvement projects th...
Mr. mohammed rabei   7 keys to successfully implement improvement projects th...Mr. mohammed rabei   7 keys to successfully implement improvement projects th...
Mr. mohammed rabei 7 keys to successfully implement improvement projects th...
 
Mr. mazen al amirah - quality is a lifestyle
Mr. mazen al  amirah - quality is a lifestyleMr. mazen al  amirah - quality is a lifestyle
Mr. mazen al amirah - quality is a lifestyle
 
Mr. aref the “100 million dollars” cultural transformation initiative
Mr. aref   the “100 million dollars” cultural transformation initiativeMr. aref   the “100 million dollars” cultural transformation initiative
Mr. aref the “100 million dollars” cultural transformation initiative
 
Dr. bibi al ajmi - quality and knowledge management what you have to do with it
Dr. bibi al  ajmi - quality and knowledge management what you have to do with itDr. bibi al  ajmi - quality and knowledge management what you have to do with it
Dr. bibi al ajmi - quality and knowledge management what you have to do with it
 
Dr. abdul hai بطاقات الأداء المتوازنالأداء الاستراتيجي واستمرارية التطوير
Dr. abdul hai   بطاقات الأداء المتوازنالأداء الاستراتيجي واستمرارية التطويرDr. abdul hai   بطاقات الأداء المتوازنالأداء الاستراتيجي واستمرارية التطوير
Dr. abdul hai بطاقات الأداء المتوازنالأداء الاستراتيجي واستمرارية التطوير
 
Mr. terje tonsberg tqm in service organizations
Mr. terje tonsberg   tqm in service organizationsMr. terje tonsberg   tqm in service organizations
Mr. terje tonsberg tqm in service organizations
 

Último

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

Último (20)

Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Evaluating the top large language models.pdf
Evaluating the top large language models.pdfEvaluating the top large language models.pdf
Evaluating the top large language models.pdf
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 

Mr. ahmed obaid the ceo guide to implement iso 27001

  • 1. ISO 27001 The CEO Guide to implement ISO 27001
  • 2.
  • 3. ISO 27001 ISO 27002 ISO 27001 ISO 27001 ISO 9001
  • 4.
  • 5. Information can be Stolen Entered Created Lost Stored Processed Destroyed Corrupted
  • 6. Information Assets
  • 7. Information • • • • •
  • 8. What is Information? “Information is an asset which, like other important business assets, has value to an organization and consequently needs to be suitably protected.” Ref: ISO/IEC 17799:2005
  • 9. Criteria of Information Security. Confidentiality Information Security Availability Integrity
  • 10. People Processes Technology
  • 12. Information Security Management system Tangible assets Confidentiality People, Processes , Technology Intangible assets Integrity Plan | Do | Check | Act Availability ISO 27002, Code of Practice For ISO 27001, Information Information Security Management Security Management Systems – Requirement These standards are accepted as industry best practices
  • 15. ISO 27001 Statement of applicability
  • 16.
  • 17. ISO 27001 Statement of applicability
  • 18.
  • 19. Military Commercial Top Secret. Confidential. Secret. Private. Confidential. Sensitive. Sensitive. Public. Unclassified.
  • 20. ISO 27001 Statement of applicability
  • 22. ISO 27002 ISO 27001 ISO 27002 ISO 27001 Control ISO 27001
  • 23. Technical Proposal Implementation Methodology Training Process Project Documents
  • 24.
  • 28. ISO 9001 ISO 27001
  • 29. Conclusion ISO 27001
  • 31. • IT GOVERNANCE, A Manager's Guide to Data Security and ISO 27001/ISO 27002, 4th edition, Alan Calder & Steve Watkins. • Effectively Managing Information Security Risk, A guide for executives, Citadel Information Group, Inc. , January, 2007 • http://iso27001standard.com.

Notas del editor

  1. information to flow seamlessly from one part of the organization to another.information entered by : a data entrydata stored by information systems, ...data processed by software and hardware systemsInformation Transferred By Clients
  2. الخصوصية : ضمان أن المعلومات متوافرة للأشخاص المفوض لهم الحصول عليها.التكاملية : توثيق دقة و اكتمال المعلومات و اساليب الإستعمال.التوافر : تأكيد أن مستخدم المعلومات المصرح لهم يتاح لهم المعلومات و الأصول المساعدة في حالة الإحتياج اليها.
  3. الخدمة هي عبارة عن نواتج 1- الإجراءات (processes) التي تنفذ عن طريق2- الاشخاص ((peoples و مدعومة من 3- التكنولوجيا (technology
  4. Intangible assets are nonphysical resources and rights that have a value to the firm because they give the firm some kind of advantage in the market place. Examples of intangible assets are goodwill, copyrights, trademarks, patents and computer programs
  5. قد يبدو امرا بديهيا، لكنه لا يؤخذ بجدي كافيةعدم الحصول على دعم الإدارة العليا من الأسباب الأساسية لفشل مشاريع التأهل للحصول على الشهادةجوهر مشروع التأهل هو تغيير ثقافة و طريقة تعامل الموظفين مع تكنولوجيا المعلومات.تكليف فريق عمل بدون إعطاءه صلاحيات / عدد كافى من الموظفين / ميزانية كافية ، ستجعل فريق العمل يواجه أوقاتا عصيبة فى محاولة لتغيير الكثير من نظم العمل.