ISO/IEC 27001:2005 (previously BS 7799) Standard provides a structured set of specifications to assist organizations in developing their own information security framework. The standard relates to all information assets in an organization covering the entire gamut of information security right from Organization, Policies, Physical environment unto the more technical and procedural concerns of Access Control, Networking, System Development, Business Continuity, Incident Management and Compliance.
ISO 27001:2005 promotes a process approach by establishing an Information Security Management System (ISMS) based on the PDCA (Plan-Do-Check-Act) Model to organizations in developing their own information security framework. The ISO/IEC 27001:2005 Standard is supported by the ISO/IEC 27002:2005 (previously ISO 17799).
The TVSNet Professional Approach
TVSNet Approach Model is based on our expertise in implementing ISMS in diversified industries and Information security environments. We do a detailed study of the environment and create a thorough profile of the organization before planning for ISMS implementation
Our Step by Step approach assures continuity and completeness in the coverage of ISMS.
The ISMS implementation process is a high quality approach that ensures relevant and adequate Information Security environment and supports the business cause and costs.
The service is offered in a modular form and is customizable to suit specific needs.
Current State Assessment – Gap Analysis
Information Security Scope and Organization
Asset Profiling
Vulnerability and Risk Assessment
Risk Treatment with business focus
Network Architecture Review, Vulnerability Assessment and Penetration Testing
Creation of policies and Procedures for effective and efficient ISMS framework
ISMS framework based on vendor and technology independent ISO 27001 guidelines
Awareness and Training
Business Continuity Framework
Incident Management
Effectiveness Measurement of Controls
Implementation Support
Effective and relevant audit mechanisms
These modules can be considered in isolation if certification is not your end goal.