ISO/IEC 27001 ISMS controls and requirements - Auditors View

所在平台: Udemy

课程主页: https://www.udemy.com/course/isoiec-27001-isms-controls-and-requirements-auditors-view/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:ISO/IEC 27001 信息安全管理体系(ISMS)控制与要求 - 审计员视角 课程概述:通过本课程,您将能够: 1. 设计并实施符合ISO/IEC 27001主要内容中所有强制性元素的ISMS。 2. 确定并评估对您ISMS范围内的组织部分构成的信息安全风险。 3. 系统性地检查并记录您的安全风险和控制状态。 4. 一旦您的ISMS正常运营、度量指标良好并收集了充分的证据,可由认证机构进行正式合规审计。 ISO 27001的适用性:ISO 27001是国际标准,提供最佳实践信息安全管理体系(ISMS)的规范和合规要求。ISO 27001提供规范,而ISO 27002则提供行为准则与推荐最佳实践,以帮助执行规范。 ISMS的好处: - 应对不断演变的安全威胁:ISMS能够不断适应环境和组织内部的变化,降低风险。 - 改善公司文化:ISMS的整体方法覆盖整个组织,使员工能够理解风险并将安全控制纳入日常工作实践。 - 保护各种信息:ISMS有助于保护所有形式的信息,无论是数字化、纸质还是云存储。 - 提高对攻击的韧性:实施并维护ISMS显著增强组织对网络攻击的抵御能力。 - 集中管理信息:ISMS提供一个中心框架,以安全地管理组织的信息。 - 降低信息安全相关成本:通过风险评估和分析方法,ISMS可减少不必要的防御技术支出。 - 保护数据的机密性、可用性和完整性:ISMS提供一整套政策、程序、技术和物理控制措施,以保护信息的机密性、可用性和完整性。 该课程适合希望深入了解ISMS的专业人士,以及希望实施ISO 27001标准的组织。

课程评论(0条)

课程详情

At the end of the course you will be able to 1. Design and implement an ISMS complying with all the mandatory elements specified in the main body of ISO/IEC 27001, 2. Identify and assess the information security risks facing those parts of the organization that are declared in scope for your ISMS, 3. Systematically check and record the status of your security risks and controls, 4.Once your ISMS is operating normally, the metrics are looking good and you have amassed sufficient evidence , it can be formally audited for compliance with '27001 by an accredited certification body.Where does ISO 27001 fit in?ISO 27001 is the international standard that provides the specification for a best-practice ISMS and covers the compliance requirements.While ISO 27001 offers the specification, ISO 27002 provides the code of conduct - guidance and recommended best practices that can be used to enforce the specification.Benefits of an ISMSAn ISO 27001-compliant ISMS does more than simply help you comply with laws and win business. It a can also:Respond to evolving security threats: Constantly adapting to changes both in the environment and inside the organisation, an ISMS reduces the threat of continually evolving risks.Improve company culture: An ISMS's holistic approach covers the whole organisation, not just IT. This enables employees to readily understand risks and embrace security controls as part of their everyday working practices.Secure your information in all its forms: An ISMS helps protect all forms of information, whether digital, paper-based or in the Cloud.Increase your attack resilience: Implementing and maintaining an ISMS will significantly increase your organisation's resilience to cyber attacks.Manage all your information in one place: An ISMS provides a central framework for keeping your organisation's information safe and managing it all in one place.Reduce costs associated with information security: Thanks to the risk assessment and analysis approach of an ISMS, organisations can reduce costs spent on indiscriminately adding layers of defensive technology that might not work.Protect the confidentiality, availability and integrity of your data: An ISMS offers a set of policies, procedures, technical and physical controls to protect the confidentiality, availability and integrity of your information.

课程标签

0人关注该课程

主题相关的课程