Search
Topics
  Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Downloads
· FAQ
· Feedback
· Forums
· Papers
· Statistics
· Surveys
· Top 10
· Topics
· Web Links
· Your Account

Who's Online
There are currently, 22 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

ISO17799 Search



Languages
Select Interface Language:


ISO 17799 Resources
There are now quite a few BS7799, ISO27001 and ISO 17799 portals on the web offering commercial tools & products. Possibly the most complete is ISO 17799 and ISO 27001 Central.

Call for Papers
We are shortly to launch a content section for papers and articles on ISO 17799 implementation, BS7799, AS4444, ISO 27001, UNE71502, and information security generally. If you have produced a paper and would like us to publish it, please contact us via the feedback form above.

ISO 27001, ISO 27002 & ISO17799 User Group: Forums

17799.Com :: View topic - Scoping
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Scoping

 
Post new topic   Reply to topic    17799.Com Forum Index -> Scoping ISO 17799 and/or ISO 27001
View previous topic :: View next topic  
Author Message
vpalat
Newbie
Newbie


Joined: Jul 29, 2004
Posts: 6
Location: Bangalore - India

PostPosted: Thu Jul 29, 2004 8:29 pm    Post subject: Scoping Reply with quote

I am attempting to define the minimum scope required for BS7799 certification for the organization I work for. I am up against a wall because we are trying to isolate IT from the scope - but all the processes defined within the scope use IT applications and Server space. Is this a problem? Or can i seperate the 2? More importantly - am I approaching this the right way?
Back to top
View user's profile
Padgetto
Guest





PostPosted: Fri Sep 17, 2004 1:37 am    Post subject: Scoping Reply with quote

IT cuts right through the organisation and is one of the main information delivery and processing tools so it's going to be difficult to isolate it from the 7799 scope. Really what you need to do first is start a little higher. Remember that BS7799 is a quality standard and as with all quality standards the main reason for adoption is to A/ Increase sales B/ reduce losses so you start at that point with a business/Information risk assessment i.e. what Information/processing assets are important to the business and what role do they play. Is it the availability of information that’s important, what will happen to what areas of the business if Information isn't available or is not correct, do you rely on ecommerce for revenue, if so how much does it bring in, what regulations do you have to adhere to and what will happen if you don't comply.

From this type of questioning you can then start to see the important Information/processing assets and the IT that is relevant to these assets.

This will help define the scope and understand the relationship with the IT. I really don't think that you can completely isolate IT and really shouldn't be doing so as the two are inherently linked.


Hope this helps
Back to top
Biljana
Newbie
Newbie


Joined: Jun 23, 2005
Posts: 20

PostPosted: Thu Nov 10, 2005 7:58 pm    Post subject: Reply with quote

I have a similar question too: my company wants to put a scope on its IT department, and we are not an IT company, and I keep telling them it would be a wrong scope, but they think this way: if information is kept in their IT systems, and the IT supports all other processes, why shouldn't we scope the IT and then force everything else from the IT (all the way to deputies' clean desk policies)?
And they say - standard is almost all about IT anyways, so why bother... we can push it all from IT... and the CEO wants it that way too. What to do?
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic    17799.Com Forum Index -> Scoping ISO 17799 and/or ISO 27001 All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Powered by phpBB 2.0.8 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

Forums ©

 
The ISO 17799 Implementation Forum: A BS7799 / ISO27001, ISO17799 and ISO 27000 User Group
All logos and trademarks are property of their respective owner. Comments are property of their posters. The rest © 2005 ISO17799 / ISO 27002 Forum
AKA: BS 7799, SPE 20003, SS 627799, JIS X 5080, AS/NZS 4444, ISO 27001. Other links: UKAS accreditation body. SV
Website source phpnuke.org (c) 2003, and is Free Software under GNU / GPL licence. All Rights Are Reserved.