ISO 27001 : 2013 ISMS - Foundation
Exam Code: ISO_ISMS_Fnd
It can also lead to new business opportunities with security-conscious customers; it can improve employee ethics and strengthen the notion of confidentiality throughout the workplace. It also allows you to enforce and reduce the possible risk of fraud, information loss and disclosure. An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes.
There are three core principles involved in ISO 27001:2013 ISMS confidentiality, integrity and availability, which cover eleven areas:
- Security policy;
- Organisation of information security;
- Asset management;
- Human resources security;
- Physical and environmental security;
- Communications and operations management;
- Access control;
- Information systems acquisition, development and maintenance;
- Information security incident management;