Search
Topics
  Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Downloads
· FAQ
· Feedback
· Forums
· Papers
· Statistics
· Surveys
· Top 10
· Topics
· Web Links
· Your Account

Who's Online
There are currently, 22 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

ISO17799 Search



Languages
Select Interface Language:


ISO 17799 Resources
There are now quite a few BS7799, ISO27001 and ISO 17799 portals on the web offering commercial tools & products. Possibly the most complete is ISO 17799 and ISO 27001 Central.

Call for Papers
We are shortly to launch a content section for papers and articles on ISO 17799 implementation, BS7799, AS4444, ISO 27001, UNE71502, and information security generally. If you have produced a paper and would like us to publish it, please contact us via the feedback form above.

ISO 27001, ISO 27002 & ISO17799 User Group: Forums

17799.Com :: View topic - Certificacion Question
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Certificacion Question

 
Post new topic   Reply to topic    17799.Com Forum Index -> BS7799 / ISO 27001 Certification Issues
View previous topic :: View next topic  
Author Message
iki
Newbie
Newbie


Joined: Mar 02, 2005
Posts: 21

PostPosted: Thu Mar 03, 2005 2:55 am    Post subject: Certificacion Question Reply with quote

hi,

I am thinking in certificate my ISMS with BS 7799:2 but there is something i dont undertand.
Imagine i have finished a published my policies, i have made a risk assesment and i have select the controls i need from ISO 17799.

After that i have programmed the implementation of all the the controls. (In two years for example) ¿Do i have to implement all the controls before going to the certification or is it enough with the risk management programm?

Thanks
Back to top
View user's profile Send e-mail MSN Messenger
Arviragus
Newbie
Newbie


Joined: Dec 17, 2004
Posts: 22
Location: Ontario, Canada

PostPosted: Sat Mar 12, 2005 2:35 am    Post subject: Good start... Reply with quote

It sounds like you have made a great start and are on the right path, but having the paper work in place isn't sufficient by itself (remember Plan-Do-Check-Act). You might want to conduct a pre-audit to identify if what you have in place is sufficient and move on from there.
_________________
Cheers,
Arviragus

"Paranoia is the only sane approach. In this business, you would be crazy not to be paranoid."
Back to top
View user's profile
Equus08
Newbie
Newbie


Joined: Mar 17, 2005
Posts: 3

PostPosted: Fri Mar 18, 2005 12:35 am    Post subject: Reply with quote

Implementation is critical to verify effectiveness of the selected controls based on the results of your risk assessment.

Documenting the policies and procedures and conducting the risk assessment process are just "some" of the activities.

ARVIRAGUS is right in higlighting the PDCA cycle.

Cheers!
Back to top
View user's profile Send e-mail
Display posts from previous:   
Post new topic   Reply to topic    17799.Com Forum Index -> BS7799 / ISO 27001 Certification Issues All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Powered by phpBB 2.0.8 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

Forums ©

 
The ISO 17799 Implementation Forum: A BS7799 / ISO27001, ISO17799 and ISO 27000 User Group
All logos and trademarks are property of their respective owner. Comments are property of their posters. The rest © 2005 ISO17799 / ISO 27002 Forum
AKA: BS 7799, SPE 20003, SS 627799, JIS X 5080, AS/NZS 4444, ISO 27001. Other links: UKAS accreditation body. SV
Website source phpnuke.org (c) 2003, and is Free Software under GNU / GPL licence. All Rights Are Reserved.