flexiolz.blogg.se

Iso 27001 documentation toolkit
Iso 27001 documentation toolkit






There are two reasons why managing assets is important:ġ) Assets are usually used to perform the risk assessment – although not mandatory by ISO 27001:2022, assets are usually the key element of identifying risks, together with threats and vulnerabilities. Why are assets important for information security management? A.5.11 – Return of assets: upon termination of business relations, all users in possession of information assets need to return them to the organization.A.5.10 – Acceptable use of information and other associated assets: rules for proper use of assets need to be defined, documented, and implemented.Asset ownership is one of the fundamental concepts in ISO 27001. A.5.9 – Inventory of information and other associated assets: all information and related assets need to be identified and have an owner responsible for protecting the confidentiality, integrity, and availability of the information.Outsourced services – e.g., legal services or cleaning services, but also online services like Dropbox or Gmail – it is true that these are not assets in the pure sense of the word, but such services need to be controlled very similarly to assets, so they are very often included in the asset management.Īlthough ISO 27001 does not have a formal definition for asset management, it has three specific controls in its Annex A to ensure proper asset management (which can be understood in an ISO 27001 context as ensuring the asset protection while the asset is important to the organization):.People are also considered assets because they also have lots of information in their heads, which is very often not available in other forms.Infrastructure – e.g., offices, electricity, air conditioning – because those assets can cause lack of availability of information.

iso 27001 documentation toolkit

  • Information – not only in electronic media (databases, files in PDF, Word, Excel, and other formats), but also in paper and other forms.
  • Software – not only the purchased software, but also freeware.
  • iso 27001 documentation toolkit

  • Hardware – e.g., laptops, servers, printers, but also mobile phones or USB memory sticks.
  • iso 27001 documentation toolkit

    Since ISO 27001 focuses on preservation of confidentiality, integrity and availability of information, this means that assets can be:

  • A.5.10 – Acceptable use of information and other associated assetsįirst, let’s clarify what assets means in the context of ISO 27001 – strangely enough, neither the 2022 revision of ISO/IEC 27001, nor the 2018 revision of ISO/IEC 27000, gives a definition of assets, but the 2005 revision of ISO/IEC 27001 defines an asset as “anything that has value to the organization.”.
  • A.5.9 – Inventory of information and other associated assets.







  • Iso 27001 documentation toolkit