Search
Topics
  Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Downloads
· FAQ
· Feedback
· Forums
· Papers
· Statistics
· Surveys
· Top 10
· Topics
· Web Links
· Your Account

Who's Online
There are currently, 22 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

ISO17799 Search



Languages
Select Interface Language:


ISO 17799 Resources
There are now quite a few BS7799, ISO27001 and ISO 17799 portals on the web offering commercial tools & products. Possibly the most complete is ISO 17799 and ISO 27001 Central.

Call for Papers
We are shortly to launch a content section for papers and articles on ISO 17799 implementation, BS7799, AS4444, ISO 27001, UNE71502, and information security generally. If you have produced a paper and would like us to publish it, please contact us via the feedback form above.

ISO 27001, ISO 27002 & ISO17799 User Group: Forums

17799.Com :: View topic - Info Assets Classification
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Info Assets Classification

 
Post new topic   Reply to topic    17799.Com Forum Index -> Dr Watson's Security Surgery
View previous topic :: View next topic  
Author Message
esanchezm
Newbie
Newbie


Joined: Mar 31, 2005
Posts: 1

PostPosted: Fri Apr 01, 2005 3:45 am    Post subject: Info Assets Classification Reply with quote

Hi,

I'm new to the forum but I wanted to get some information from more experienced ISO17799 users on Informaton Assets Classification. I'm working towards completing my MS degree doing a thesis completely focused on ISO 17799 - Information Assets Classification and Controls. I know it looks simple and narrow, but my goal is to document processes and guidelines for Info Assets classification in a multinational company (Think of lots and lots of information ). What I'm looking for initially is basic information on what steps need to be followed for assets identification and classification (and of course labeling). I only need a framework or blueprint where I can base and expand my own work. Do you know of any web links, books, white papers, etc. I can use for this work?

Thanks in advance,

Lalo
lalosm@yahoo.com
Back to top
View user's profile
DavidWatson
Newbie
Newbie


Joined: Nov 02, 2005
Posts: 9
Location: Isle of Wight

PostPosted: Fri Nov 18, 2005 5:54 am    Post subject: Reply with quote

Hi

This clause sounds simple but is one of the most difficult to implement

I will split it into two

Assets

The service or help desk should have a list of all physical IT assets and these should be labelled and audited annually

Information assets have to be determiend by talking to the business or examining all servers (and maybe critical PCs) to determine what applications run on them.

If you are lucky the IT Department may hold such a list (I always live in hope - and if they do is it accurate and up to date?)

There are other assets such as services supplied to the orgainsation, staff, gas, electric, phones, water etc

Additionally - reputation is the biggest asset in many organisations

There may be others and this will vary from organisation to organsation - they could include raw materials, stock, work in progess, money, buildings, cars - the list is endless and depends on the organisation

Classification

Well - we have probably all seen James Bond and have seen the cover of a 'Top Secret' file - but what does that mean

One of the best sites for reading about a classification system is (for the UK and to understand the confidentiality requirements):

http://www.dti.gov.uk/industry_files/pdf/confidential.pdf

However, each country and perhaps company has its own views on the subject and you should reseach the issue (Any search engine will keep you amused for hours!)

This marking scheme has a drawback that it only really deals with confidentiality and you may be responsible for high value cash payments which may not be confidential but are a lot of money (Million or Trillions).

Given this classification procedure there would be little protection granted so we need to include payment values as well

There are also the needs for protecting for integrity and availability - a high available system (i.e. on line transaction processing system vs shop window advert)

It will all depend on the business that you are in and what you need to protect and from what protection is needed

I am afraid it is up to you or the organisation to decide, but experience dictates that whatever you decide there will be lots of people who disagree

Once agreed - the real fun comes trying to implement the process including labelling and handling!

Dr Watson
Back to top
View user's profile Send e-mail Visit poster's website
okay
Newbie
Newbie


Joined: Mar 23, 2007
Posts: 5

PostPosted: Sat Mar 24, 2007 1:56 am    Post subject: Reply with quote

Hi,

I saw your request in the forum of ISO 17799. I would have a scope: information assets.

information assets is all the data process, store and communicated that has value to the organization, for example, the information of the clients is confidential, the strategy plan is secret .....

This document from Gartner can help you start with the process

listserv.educause.edu/cgi-bin/wa.exe?A3=ind0612&L=cio&P=956638&E=2&B=--%3D__Part8FAB40FE.0__%3D&N=adopt_an_information_classif_125064.pdf&T=application%2Fpdf


Best regards
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic    17799.Com Forum Index -> Dr Watson's Security Surgery All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Powered by phpBB 2.0.8 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

Forums ©

 
The ISO 17799 Implementation Forum: A BS7799 / ISO27001, ISO17799 and ISO 27000 User Group
All logos and trademarks are property of their respective owner. Comments are property of their posters. The rest © 2005 ISO17799 / ISO 27002 Forum
AKA: BS 7799, SPE 20003, SS 627799, JIS X 5080, AS/NZS 4444, ISO 27001. Other links: UKAS accreditation body. SV
Website source phpnuke.org (c) 2003, and is Free Software under GNU / GPL licence. All Rights Are Reserved.