ISO IEC 17799 2000*TRANSLATED INTO PLAIN ENGLISHSection 12: ComplianceDETAILED STANDARD |
||
|
* ISO
17799 is now OBSOLETE. |
||
![]()
|
12.1 COMPLY WITH LEGAL REQUIREMENTS |
|
|
|
Make sure that your information systems comply
|
|
|
Make sure that your information systems comply
|
|
|
Make sure that your information systems comply
|
|
|
Make sure that your information systems comply
with |
|
|
Consult with legal experts in order to ensure
that your |
|
12.1.1 IDENTIFY ALL RELEVANT LEGAL REQUIREMENTS |
|
|
|
Identify and document all relevant statutory
requirements |
|
|
Identify and document all relevant regulatory
requirements |
|
|
Identify
and document all relevant
contractual requirements |
|
|
Identify and document the controls that you
need |
|
|
Identify and document the controls that you
need |
|
|
Identify and document the controls that you
need |
|
|
Identify and document the individual
responsibilities |
|
|
Identify and document the individual
responsibilities |
|
|
Identify and document the individual
responsibilities |
|
12.1.2 RESPECT INTELLECTUAL PROPERTY RIGHTS |
|
|
12.1.2.1 CREATE INTELLECTUAL PROPERTY PROCEDURES |
|
|
|
Establish
procedures to ensure that your organization |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
12.1.2.2 COMPLY WITH ALL SOFTWARE COPYRIGHTS |
|
|
|
Develop a software copyright compliance policy. |
|
|
Make sure that your copyright compliance
policy explains |
|
|
Make sure that your copyright compliance
policy explains |
|
|
Develop policies and standards to control the purchase of software. |
|
|
Make personnel aware of software compliance and purchasing policies. |
|
|
Make it clear that your organization will take
disciplinary action whenever |
|
|
Maintain a register of all proprietary software and information assets. |
|
|
Make sure that you can prove that you own all
your software |
|
|
Establish controls to ensure that you do not
exceed the maximum |
|
|
Perform checks to ensure that only licensed
and |
|
|
Develop a policy to control the maintenance
|
|
|
Develop a policy to control the disposal
or transfer |
|
|
Ensure that appropriate tools are used to
audit |
|
|
Ensure that you comply with the legal terms
and |
|
12.1.3 SAFEGUARD YOUR ORGANIZATION’S RECORDS |
|
|
|
Protect your organization’s important records. |
|
|
Protect your important records from loss. |
|
|
Implement controls to protect your important
|
|
|
Protect your important records from destruction. |
|
|
Implement controls to protect your important
and |
|
|
Protect your important records from falsification. |
|
|
Implement controls to protect your important
and |
|
|
Make sure that records are securely retained
whenever |
|
|
Make sure that records are securely retained
whenever |
|
|
Store cryptographic keys in a secure manner. |
|
|
Make sure that your records can prove that
your organization |
|
|
Make sure that your records
can provide the evidence needed to |
|
|
Make sure that your records allow you to
retrieve information in a |
|
|
Make sure that your records
can provide the evidence needed to |
|
|
Make sure that the
information content and structure of your |
|
|
Make sure that your record
retention time periods comply |
|
|
Categorize your records into different types
|
|
|
Make sure that your organization has
established |
|
|
Make sure that you establish a record
retention schedule
that |
|
|
Establish procedures to ensure that electronic
records |
|
|
Specify what type of storage media |
|
|
Protect your records against the possible |
|
|
Make sure that your storage media are handled
in accordance |
|
|
Make sure that your storage and handling
system |
|
|
Make sure that your storage and handling
system ensures |
|
|
Make sure that your storage and handling
system allows you to destroy |
|
|
Establish guidelines to control the storage,
|
|
|
Maintain an inventory that lists your
organization’s key |
|
12.1.4 PROTECT THE PRIVACY OF PERSONAL INFORMATION |
|
|
|
Protect the privacy of personal information
when that |
|
|
Make sure that your organization complies with
all relevant |
|
|
Make sure that your organization complies with
all relevant legislation |
|
|
Set up management structures and controls to
ensure that your |
|
|
Appoint a data protection officer to provide
guidance |
|
|
Make sure that your personal data protection
officer helps |
|
|
Make sure that your personal data protection
officer |
|
|
Make sure that your personal data protection
officer |
|
|
Make data owners responsible for telling your
data |
|
|
Make data owners responsible for making sure
that |
|
12.1.5 PREVENT MISUSE OF DATA PROCESSING FACILITIES |
|
|
|
Ensure that your information processing
facilities are not |
|
|
Monitor the use of your information processing
facilities |
|
|
Get legal advice before you start monitoring
the |
|
|
Make sure that your monitoring of information
processing |
|
|
Ensure that unauthorized personal or
non-business use of |
|
|
Make sure that your managers take disciplinary
action |
|
|
Ensure that computer user access rights and
|
|
|
Ensure that all users are aware of the precise
legal limits that are imposed |
|
|
Ensure that users receive written
authorization to access |
|
|
Ensure that your employees understand that
they must |
|
|
Ensure that third party users understand that
they must |
|
|
Use on‑screen warning messages to tell users
|
|
|
Expect users to acknowledge on‑screen warnings
|
|
12.1.6 CONTROL THE USE OF CRYPTOGRAPHIC CONTROLS |
|
|
|
Ensure that access to or use of
cryptographic controls |
|
|
Get legal advice to ensure that your access to
or use |
|
|
Get legal advice before you decide to transfer
|
|
|
Get legal advice before you decide to transfer
|
|
|
Get legal advice before you decide to import
computer |
|
|
Get legal advice before you decide to export
computer |
|
|
Get legal advice before you decide to import
computer |
|
|
Get legal advice before you decide to export
computer |
|
|
Get legal advice before you decide to import
computer hardware that |
|
|
Get legal advice before you decide to export
computer hardware that |
|
|
Get legal advice before you decide to import
computer software that |
|
|
Get legal advice before you decide to export
computer software that |
|
|
Get legal advice whenever countries wish to
have access to |
|
12.1.7 COLLECT EVIDENCE TO SUPPORT YOUR ACTIONS |
|
|
12.1.7.1 COMPLY WITH APPROPRIATE RULES OF EVIDENCE |
|
|
|
Make sure that you collect evidence to support
actions that |
|
|
Make sure that you collect evidence to support
potential |
|
|
Develop internal procedures that specify what
kind of evidence is needed |
|
|
Make sure that you collect evidence to support
potential civil or criminal |
|
|
Make sure that your evidence will comply with
the rules of evidence |
|
|
Make sure that your evidence will be
admissible |
|
|
Safeguard the quality and completeness of your
|
|
|
Make sure that you can prove that your process
controls are working |
|
12.1.7.2 GATHER EVIDENCE THAT IS ADMISSIBLE IN COURT |
|
|
|
Identify a published standard or code
of practice that you |
|
|
Make sure that your information systems comply
|
|
12.1.7.3 PROTECT THE QUALITY OF YOUR EVIDENCE |
|
|
|
Establish a strong trail of evidence whenever
an |
|
|
Establish a strong trail of evidence whenever
an incident |
|
|
Establish a strong trail of evidence whenever
an incident |
|
|
Establish a strong trail of evidence whenever
|
|
|
Establish a strong trail of evidence whenever
an incident |
|
|
Establish a strong trail of evidence whenever
an incident occurs |
|
|
Establish a strong trail of evidence whenever
an incident occurs |
|
|
Establish a strong trail of evidence
whenever an incident occurs |
|
|
Establish a strong trail of evidence whenever
an incident occurs |
|
|
Establish a strong trail of evidence whenever
an incident |
|
|
Establish a strong trail of evidence whenever
an incident occurs |
|
|
Involve a lawyer or the police as early as
possible whenever you believe |
|
12.2 PERFORM SECURITY COMPLIANCE REVIEWS |
|
|
|
Review regularly the security of your information systems. |
|
|
Review the security of your information
systems by examining |
|
|
Review the security of your information
systems by examining |
|
12.2.1 REVIEW COMPLIANCE WITH SECURITY POLICY |
|
|
|
Review regularly how well your organization
|
|
|
Review regularly how well your organization
|
|
|
Review regularly how well your organization
|
|
|
Review regularly how well your information
systems |
|
|
Review regularly how well systems providers
|
|
|
Review regularly how well owners of
information |
|
|
Review regularly how well users comply |
|
|
Review regularly how well your management |
|
|
Make sure that owners of information systems
|
|
12.2.2 REVIEW TECHNICAL SECURITY COMPLIANCE |
|
|
|
Check regularly your information systems to
ensure |
|
|
Examine your operational systems to ensure
that |
|
|
Examine your operational systems to ensure
that |
|
|
Make sure that all technical compliance checks
are |
|
|
Use technical security specialists to help you
|
|
|
Use technical security specialists to help you
to interpret |
|
|
Use experienced system engineers to |
|
|
Carry out penetration tests in order to detect
|
|
|
Carry out penetration tests in order to check
|
|
|
Ensure that your penetration tests do not |
|
12.3 CARRY OUT OPERATIONAL SYSTEM AUDITS |
|
|
|
Perform audits of your operational systems. |
|
|
Establish controls to safeguard operational
|
|
|
Establish controls to safeguard audit software
and |
|
|
Establish controls to safeguard the integrity
|
|
|
Establish controls to prevent the misuse |
|
12.3.1 PLAN THE AUDIT OF OPERATIONAL SYSTEMS |
|
|
|
Plan your operational audit activities and
requirements in order to |
|
|
Control your operational audit activities and
requirements in order to |
|
|
Make sure that your audit activities and
requirements are approved by |
|
|
Make sure that agreement is reached on the
scope of your audit |
|
|
Make sure that audit checks are limited to
read‑only |
|
|
Make sure that only isolated copies of
operational |
|
|
Make sure that isolated copies of operational
system files |
|
|
Make sure that IT resources needed to perform
audit |
|
|
Make sure that needed IT resources are made
available |
|
|
Make sure that any special requirements for
additional |
|
|
Monitor and log all access to operational |
|
|
Document all audit procedures. |
|
|
Document all audit requirements. |
|
|
Document all audit responsibilities. |
|
12.3.2 PROTECT YOUR SYSTEM TOOLS |
|
|
|
Protect your system audit tools in order to
prevent any |
|
|
Protect your system audit software in order to
|
|
|
Protect your system audit data files in order
to |
|
|
Segregate your system audit tools from |
|
|
Provide special security protection for audit
tools |
|
PRAXIOM RESEARCH GROUP
LIMITED |
|||
|
Updated on December 22, 2011. First published on October 28, 2004. |
|||
Disclaimer
and Limitation of Liability
The
publisher and authors have used their best efforts in designing and
developing this electronic publication. We make no representation or
warranties
with respect to accuracy or completeness of the contents of
this publication and
specifically disclaim any implied warranties or
merchantability or fitness for any
particular purpose and shall in no
event be liable for any loss of profit or any
other commercial damage,
including but not limited to special, incidental,
consequential, or
other damages.
Legal
Restrictions on the Use of this Page
Thank
you for visiting this page. You are, of course, welcome to view our
material as often as you wish, free of charge. And as long as you
keep intact
all copyright notices, you are also welcome to print or make one
copy of this
page for your own personal, noncommercial, home use. But, you are not
legally authorized to print or produce additional copies or to
copy and paste
any of our material onto another web site or to republish it in
any way.
Copyright © 2004-2012 by Praxiom Research Group Limited. All Rights Reserved.
![]()