Secode Goals and Strategy |
|
Secode produce a document that will provide an overview of which security requirements and guidelines apply to your company, both in terms of technical IT solutions and the organizational and administrative security conditions. The document was created based on BS7799, with a practical approach to the company's security needs so that is can be used over the entire life of the IT system, and becomes an important part of the company, so that security issues are taken into consideration as a matter of necessity over time. Implementation and work method Secode emphasizes that the creation of this document is a process involving close cooperation with the companies own personnel, so that the contents of the document become a part of the everyday life of the company. This ensures that the document becomes a "living document" and that it takes care of the need for services. At the same time, it should help ensure that potential threats are treated with the correct security level for mission-critical functions. It is recommended that this document be created simultaneously or after completing risk analyses, so that the need for services and relevant threats can be considered when forming the company's security policy, requirements and measures.
The extent and depth of this document will vary based on the type of business in question. In addition to the results of risk analyses, BS7799 also acts as a standard, and the document will have the following subsections:
Security goals and strategy, security organization and responsibility Aimed at the management and will form the basis for their decision regarding the need for security in the company Threats, potential loss and categorization of information and services Will be based on the need for security System technical and organizational security measures The security measures have consequences for users, and the details in this regard are outlined in manuals aimed at various user groups Maintaining security over time Critical steps such as risk analysis, configuration review, deviation control, and management review to ensure that the systems maintain the established level of security over time. Results The document will be a living document that will help ensure that information management and electronic services help the business grow appropriately, without having the electronic systems expose the company to threats and undesired events.
|