An information security management system (ISMS) is not only a set of documented rules and instructions. It really is a systematic, continuous and long-term process to establish the optimal level of information security based on the unique threats and requirements of the organization. A fully functioning ISMS will be integrated within the key processes of the organization, such as the management processes, procurement, development, IT production and maintenance, HR and finance. It requires the understanding, commitment and support of the Executive Board, cooperation between professional roles and functions, well defined responsibilities and clarity on reporting requirements. At the core of information security, you need to identify and classify your information assets and execute a systematic risk assessment and risk ownership. This will guide your execution of the required risk management measures and responsibilities that will provide the protection levels needed for IT system, organization and physical security.
Veriscan has worked within information security since 1999 and have supported a large number of ISMS implementations in different kinds of organizations, such as central government, county councils and small and large private companies in various industries. There can be a large variety in scope in these projects, from the immature organization entering the domain of information security to an organization that is experienced with an ISMS in operation and with a goal of certification towards ISO/IEC 27001. Many organizations do have an ISMS in place but have a need to update and improve the level of the ISMS protection due to changes in the organization, supplier relationships and external factors. Sometimes we come across ISMS implementations not fit to the real need of the organization, or with vague objectives, with the consequence that it becomes a set of rules and instructions of no limited value to the organization. Here are a few examples of ongoing and finalized ISMS implementation projects;
These are just a few examples of the clients we have worked with and continuous to support regularly with ISMS improvement work. In most cases Veriscan becomes a long-term information security partner, as an advisor or for specific tasks such as internal audits, preparation for certification, develop information security guidelines and education or to execute measurements of the performance of the clients ISMS (Veriscan Rating).
Based on ISO/IEC 27001 and other relevant ISO-standards, your unique situation and your internal and external requirements, we can support you in developing rules, instructions and processes covering roles, responsibilities, information classification and relevant security protection levels. We can provide you with project management for ISMS implementation or provide assistance your assigned project manager with competence and experience to handle the questions and challenges surfacing during the project.
Using our Veriscan tools for information classification and risk management, Veriscan vIC and VeriscanRISK, we support you in assessment, risk measure decisions and the development of methods as well as in executing workshops and education within your organization. We can also support you in developing processes and requirements on risk protection levels for information towards your information asset owners. If you already have your own tools implemented, we will of course work with them. Throughout the projects you will often find use for different methods and tools to secure the success of the project. A few examples on this;
Our ambition is to support your organization to become self-sufficient and build your competence in developing and implementing an ISMS that is adapted to your organization.
For more information please contact Veriscan.
Email: info@veriscan.se