IT BASIS CHECK ISO/IEC 27001: INFORMATION SECURITY
Information is an essential component of successful business processes and represents a great value that the company’s management is responsible for securing and maintaining.
Site assessment and evaluation in accordance with ISO/IEC 27001
In this context, the information technology infrastructures used to provide and process information continue to gain in importance and must meet the requirements.
The international standard ISO/IEC 27001 requires a separate process for information security and at the same time defines concrete measures. This Information Security Management System (ISMS) essentially corresponds to a quality management of the security requirements of information.
SEC4YOU carries out a site assessment with regard to the requirements of ISO/IEC 27001, determines the potential for improvement and provides concrete proposals for solutions.
Audit areas of ISO/IEC 27001:
- General conditions and security needs of the company
- Responsibility and commitment of the company management
- Dealing with risks and opportunities
- Support, awareness and communication of security objectives
- Measurement of objectives and procedures for improvement
- Guidelines and structure of the safety organization
- Safety requirements in human resources
- Handling information and responsibility
- Access protection and user management
- Use of cryptographic measures
- Physical security
- Operational security, virus protection, backup and restore, and monitoring
- Communication security
- Acquisition, development and maintenance of systems
- Security in dealing with suppliers
- Dealing with security incidents
- Security aspects in business continuity management
- Conformity with legal and contractual requirements
As a result, you will receive a written report that identifies existing weaknesses and risks and describes specific recommendations to mitigate the identified risks for your company.
FACTSHEET
YOUR ADVANTAGES
- Legal certainty through the application of the internationally recognized ISO/IEC 27001, as standards are considered “state of the art” in the event of a dispute.
- Assessment of the current status by independent experts;
- Knowledge of potential hazards and conscious consideration of risks
- Increasing the effectiveness and efficiency of the resources used for security
- Missing security measures are identified and can be remedied in a timely manner.
- You identify weak points in your IT before problems occur
Questions about the ISO 27001 Basic Check or ISO 27001 Certification?
Would you like to speak with an expert?