Policies & Standards
InfoSecure has considerable experience in establishing policies for information security based on International standards, such as the ISO 27001. A number of steps have to be taken to implement policies so that information security becomes a reality in the organisation. InfoSecure employs policies, standards, work instructions and procedures to achieve this.

General Information
Organisations depend on reliable internal and external information and information systems. Organisations are required to operate secure systems while having to respond to increased levels of threats to information processing. Organisations are increasingly employing a standard for implementing and improving knowledge of information security such as ISO 27001 International Standard.
How can InfoSecure assist you?
InfoSecure can assist you in drawing up policy & standards documents, procedures and guidelines, derived from the generic standards set out above, and in implementing policies in your organisation using the following steps: 6-steps improvement »
InfoSecure uses a generic set of templates for policies & Standards in different languages. Together with the client these templates will be customised to their requirements.
Action Plan
Information security starts with an action plan, setting out the tasks to be undertaken and the timetable for actions.
Drawing up Policy
Establishing a security organisation and drawing up policies for existing and new activities; management commitment to these policies will be required.
Support in Implementing ISO 27001
The experience gained by InfoSecure from previous implementations is that this implementation will have the greatest chance of meeting requirements if implemented directly by the client, updated on a regular basis, and embedded as a part of daily practice with InfoSecure taking a support role. A number of effective tools, such as ISRAC » and ISCAP » (ISO 27001), are available to enable the client to work independently, after only brief supervision by InfoSecure.
Support for Maintaining or Improving the Level of Information Security within a company
To be effective, security policies will require regular updating to reflect changes within the organisation, work practices, new business components and activities. InfoSecure can assist clients to implement these, using tools for risk analysis » and compliance », ensuring that employees are continuously aware of the relevance of their own behaviour within the organisation. In this respect the InfoSecure Awareness Workshops » and eLearning » are particularly useful.
InfoSecure offers a wide range of services and will be happy to work in a manner that is most beneficial to clients, offering a range of tools and programmes as well as training in their use. More info… » |