Information Security Management System (ISMS) in a company

Technology Outlook Express is used for mail communication. The company must use a range of multimedia software to produce printed goods. The company has two computers one of which is High Spec used for accounting and ordering and the other for the printers. Information security management system is a set of policies connected with information security management and information security risks. The expressions came from ISO 27001. “The principle behind ISMS is that an organisation should design, implement and maintain a clear set of policies, processes and systems to manage risks to its information assets, therefore ensuring acceptable levels of information security risk.”

ISMS should be competent in the future and should adapt to changes whether they are internal or external and therefore should integrate the Plan-Do-Check-Act cycle method which will keep it up to date. From the above the company will determine whether it is cost beneficial to place for example a lock on the stationary room, if the lock cost more than the stationary then it can indeed be seen as useless reason being that the stationary can be replaced if stolen this would be a cheaper alternative to buying a lock. But a lock could act as a deterrent to stop the theft in the first place.

Web hosting as the site is not hosted by the company is it secure and safe, is it vulnerable to attack from the web hosting side. Secure passwords should be used which use a combination keyboard keys, it is also vital to see what security measures the hosting company has in place. If a hacker gets control of the company’s website then secure card details are at risk. Online sales are being processed through the website are the credit/debit card details and customer details safe and are they being encrypted e.g. SSL, where are the details being saved and who has access to them. Is the website secure e.g. VeriSign secure SSL or MacAfee hacker tested?

Are there any validations on computerized processes that are completed by employees to reduce human error, e.g. a form would only allow alphabetical letters and not allow numbers in certain text boxes such as ‘Name’ to avoid errors, or have drop down combo boxes for dates. Data protection is also vital as data should be protected either by access control, encryption and passwords. Only allowing the accounts department access to employee payrolls would increase data protection as the risk of data theft, loss and corruption occurring is reduced. As well as that the company needing to check whether the customer data is secure and employee data is secures as well as it being backed up regularly.

The company should be ready for any threats from nature; these can include floods, hurricanes/tornadoes, and earthquakes. Each of which can have a devastating effect on the company from taking out the power to destroying the premises where they are based, threats such as these are rare and should be based upon the history of the area in which the premises are located, if near a river then floods could be likely and computers and printers should be placed above the ground floor. Power generators should be used to stop power failure in case of power cuts, but most importantly premises and content should be insured in case of major disasters which could bring down the company.

Software Attack Virus protection is vital to fight the threat of software attacks regular updates should be checked for and important patches should be installed for the OS. An IDS would detect if any attack was being made and alert the appropriate person to the attack. A ‘Honey pot’ (a decoy system fabricated with useless data) should be deployed to deter hackers to it allowing the IT Security Manager to see where the hack is originating from and to block it.

Premises The premises should have locks on doors, CCTV and alarmed so that the data on the computers inside the premises is secure and reasonable steps have been taken to secure it Conclusion: Overall to comply with ISO 27001 the company needs to start looking at risks starting within the company itself, the employees are the most likely risk, steps should be taken to implement access control to the current system. The external system should be secured by means IDPS, if that is not possible a firewall should be put in place to secure the system and configured for the company’s requirements. The website should be secured if not already even if this means moving to a different host, loosing customer data to hackers could mean a drop in sales as customers will not believe their data is safe within the company, the company being sued under the Data Protection Act 1998.

References:

http://security.practitioner.com/introduction/infosec_4_4.htm

Calculate the price
Make an order in advance and get the best price
Pages (550 words)
$0.00
*Price with a welcome 15% discount applied.
Pro tip: If you want to save more money and pay the lowest price, you need to set a more extended deadline.
We know how difficult it is to be a student these days. That's why our prices are one of the most affordable on the market, and there are no hidden fees.

Instead, we offer bonuses, discounts, and free services to make your experience outstanding.
How it works
Receive a 100% original paper that will pass Turnitin from a top essay writing service
step 1
Upload your instructions
Fill out the order form and provide paper details. You can even attach screenshots or add additional instructions later. If something is not clear or missing, the writer will contact you for clarification.
Pro service tips
How to get the most out of your experience with MyhomeworkGeeks
One writer throughout the entire course
If you like the writer, you can hire them again. Just copy & paste their ID on the order form ("Preferred Writer's ID" field). This way, your vocabulary will be uniform, and the writer will be aware of your needs.
The same paper from different writers
You can order essay or any other work from two different writers to choose the best one or give another version to a friend. This can be done through the add-on "Same paper from another writer."
Copy of sources used by the writer
Our college essay writers work with ScienceDirect and other databases. They can send you articles or materials used in PDF or through screenshots. Just tick the "Copy of sources" field on the order form.
Testimonials
See why 20k+ students have chosen us as their sole writing assistance provider
Check out the latest reviews and opinions submitted by real customers worldwide and make an informed decision.
BUSINESS LAW
excellent job made a 93
Customer 452773, March 22nd, 2023
Human Resources Management (HRM)
excellent job
Customer 452773, June 25th, 2023
History
Looks great and appreciate the help.
Customer 452675, April 26th, 2021
Business and administrative studies
perfect
Customer 452773, February 23rd, 2023
Business and administrative studies
Thank you for your hard work and help
Customer 452773, February 21st, 2023
Human Resources Management (HRM)
excellent, great job
Customer 452773, June 19th, 2023
ACC/543: Managerial Accounting & Legal Aspects Of Business
EXCELLENT JOB
Customer 452773, January 10th, 2024
Business and administrative studies
Excellent job
Customer 452773, March 17th, 2023
Criminal Justice
This has been the greatest help while I am recovering from an illness. Thank your team so much.
Customer 452671, May 2nd, 2021
Nursing
I just need some minor alterations. Thanks.
Customer 452547, February 10th, 2021
Business and administrative studies
excellent job
Customer 452773, March 12th, 2023
Leadership Studies
excellent job as always
Customer 452773, September 2nd, 2023
11,595
Customer reviews in total
96%
Current satisfaction rate
3 pages
Average paper length
37%
Customers referred by a friend
OUR GIFT TO YOU
15% OFF your first order
Use a coupon FIRST15 and enjoy expert help with any task at the most affordable price.
Claim my 15% OFF Order in Chat
Close

Sometimes it is hard to do all the work on your own

Let us help you get a good grade on your paper. Get professional help and free up your time for more important courses. Let us handle your;

  • Dissertations and Thesis
  • Essays
  • All Assignments

  • Research papers
  • Terms Papers
  • Online Classes
Live ChatWhatsApp