ISO IEC 17799 2000*TRANSLATED INTO PLAIN ENGLISHSection 12: ComplianceFREE DETAILED STANDARD |
||
| MAIN MENU | START OVER | |
|
* ISO
17799 2000 is now OBSOLETE. |
||
![]()
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
12.1 COMPLY WITH LEGAL REQUIREMENTS |
|
|
|
Make sure that your information systems comply
|
|
|
Make sure that your information systems comply
|
|
|
Make sure that your information systems comply
|
|
|
Make sure that your information systems comply
with |
|
|
Consult with legal experts in order to ensure
that your |
|
12.1.1 IDENTIFY ALL RELEVANT LEGAL REQUIREMENTS |
|
|
|
Identify and document all relevant statutory
requirements |
|
|
Identify and document all relevant regulatory
requirements |
|
|
Identify
and document all relevant
contractual requirements |
|
|
Identify and document the controls that you
need |
|
|
Identify and document the controls that you
need |
|
|
Identify and document the controls that you
need |
|
|
Identify and document the individual
responsibilities |
|
|
Identify and document the individual
responsibilities |
|
|
Identify and document the individual
responsibilities |
|
12.1.2 RESPECT INTELLECTUAL PROPERTY RIGHTS |
|
|
12.1.2.1 CREATE INTELLECTUAL PROPERTY PROCEDURES |
|
|
|
Establish
procedures to ensure that your organization |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
|
Make sure that your intellectual property
procedures |
|
12.1.2.2 COMPLY WITH ALL SOFTWARE COPYRIGHTS |
|
|
|
Develop a software copyright compliance policy. |
|
|
Make sure that your copyright compliance
policy explains |
|
|
Make sure that your copyright compliance
policy explains |
|
|
Develop policies and standards to control the purchase of software. |
|
|
Make personnel aware of software compliance and purchasing policies. |
|
|
Make it clear that your organization will take disciplinary action whenever staff members violate your software compliance and purchasing policies. |
|
|
Maintain a register of all proprietary software and information assets. |
|
|
Make sure that you can prove that you own all
your software |
|
|
Establish controls to ensure that you do not exceed the maximum allowable number of users for each proprietary software product. |
|
|
Perform checks to ensure that only licensed
and |
|
|
Develop a policy to control the maintenance
|
|
|
Develop a policy to control the disposal
or transfer |
|
|
Ensure that appropriate tools are used to
audit |
|
|
Ensure that you comply with the legal terms
and |
|
12.1.3 SAFEGUARD YOUR ORGANIZATION’S RECORDS |
|
|
|
Protect your organization’s important records. |
|
|
Protect your important records from loss. |
|
|
Implement controls to protect your important
|
|
|
Protect your important records from destruction. |
|
|
Implement controls to protect your important
and |
|
|
Protect your important records from falsification. |
|
|
Implement controls to protect your important
and |
|
|
Make sure that records are securely retained
whenever |
|
|
Make sure that records are securely retained
whenever |
|
|
Store cryptographic keys in a secure manner. |
|
|
Make sure that your records can prove that
your organization |
|
|
Make sure that your records
can provide the evidence needed to |
|
|
Make sure that your records allow you to
retrieve information in a |
|
|
Make sure that your records
can provide the evidence needed to |
|
|
Make sure that the
information content and structure of your |
|
|
Make sure that your record
retention time periods comply |
|
|
Categorize your records into different types
|
|
|
Make sure that your organization has
established |
|
|
Make sure that you establish a record
retention schedule
that |
|
|
Establish procedures to ensure that electronic
records |
|
|
Specify what type of storage media |
|
|
Protect your records against the possible |
|
|
Make sure that your storage media are handled
in accordance |
|
|
Make sure that your storage and handling
system |
|
|
Make sure that your storage and handling
system ensures |
|
|
Make sure that your storage and handling system allows you to destroy records that are no longer needed once the retention period is over. |
|
|
Establish guidelines to control the storage,
|
|
|
Maintain an inventory that lists your
organization’s key |
|
12.1.4 PROTECT THE PRIVACY OF PERSONAL INFORMATION |
|
|
|
Protect the privacy of personal information
when that |
|
|
Make sure that your organization complies with
all relevant |
|
|
Make sure that your organization complies with
all relevant legislation |
|
|
Set up management structures and controls to ensure that your organization complies with relevant personal data protection legislation. |
|
|
Appoint a data protection officer to provide
guidance |
|
|
Make sure that your personal data protection
officer helps |
|
|
Make sure that your personal data protection
officer |
|
|
Make sure that your personal data protection
officer |
|
|
Make data owners responsible for telling your
data |
|
|
Make data owners responsible for making sure
that |
|
12.1.5 PREVENT MISUSE OF DATA PROCESSING FACILITIES |
|
|
|
Ensure that your information processing
facilities are not |
|
|
Monitor the use of your information processing
facilities |
|
|
Get legal advice before you start monitoring
the |
|
|
Make sure that your monitoring of information
processing |
|
|
Ensure that unauthorized personal or
non-business use of |
|
|
Make sure that your managers take disciplinary
action |
|
|
Ensure that computer user access rights and
|
|
|
Ensure that all users are aware of the precise legal limits that are imposed on their use of your organization’s information processing facilities. |
|
|
Ensure that users receive written
authorization to access |
|
|
Ensure that your employees understand that
they must |
|
|
Ensure that third party users understand that
they must |
|
|
Use on‑screen warning messages to tell users
|
|
|
Expect users to acknowledge on‑screen warnings
|
|
12.1.6 CONTROL THE USE OF CRYPTOGRAPHIC CONTROLS |
|
|
|
Ensure that access to or use of
cryptographic controls |
|
|
Get legal advice to ensure that your access to
or use |
|
|
Get legal advice before you decide to transfer
|
|
|
Get legal advice before you decide to transfer
|
|
|
Get legal advice before you decide to import
computer |
|
|
Get legal advice before you decide to export
computer |
|
|
Get legal advice before you decide to import
computer |
|
|
Get legal advice before you decide to export
computer |
|
|
Get legal advice before you decide to import
computer hardware that |
|
|
Get legal advice before you decide to export
computer hardware that |
|
|
Get legal advice before you decide to import
computer software that |
|
|
Get legal advice before you decide to export
computer software that |
|
|
Get legal advice whenever countries wish to
have access to |
|
12.1.7 COLLECT EVIDENCE TO SUPPORT YOUR ACTIONS |
|
|
12.1.7.1 COMPLY WITH APPROPRIATE RULES OF EVIDENCE |
|
|
|
Make sure that you collect evidence to support
actions that |
|
|
Make sure that you collect evidence to support
potential |
|
|
Develop internal procedures that specify what kind of evidence is needed in order to support your organization’s internal disciplinary actions. |
|
|
Make sure that you collect evidence to support potential civil or criminal actions that may need to be taken against a person or organization. |
|
|
Make sure that your evidence will comply with the rules of evidence established by the laws and courts that effect your organization. |
|
|
Make sure that your evidence will be
admissible |
|
|
Safeguard the quality and completeness of your
|
|
|
Make sure that you can prove that your process controls are working correctly and consistently and are able to protect the quality of the evidence that is being processed and stored in your information systems. |
|
12.1.7.2 GATHER EVIDENCE THAT IS ADMISSIBLE IN COURT |
|
|
|
Identify a published standard or code
of practice that you |
|
|
Make sure that your information systems comply
|
|
12.1.7.3 PROTECT THE QUALITY OF YOUR EVIDENCE |
|
|
|
Establish a strong trail of evidence whenever
an |
|
|
Establish a strong trail of evidence whenever
an incident |
|
|
Establish a strong trail of evidence whenever
an incident |
|
|
Establish a strong trail of evidence whenever
|
|
|
Establish a strong trail of evidence whenever
an incident |
|
|
Establish a strong trail of evidence whenever
an incident occurs |
|
|
Establish a strong trail of evidence whenever
an incident occurs |
|
|
Establish a strong trail of evidence
whenever an incident occurs |
|
|
Establish a strong trail of evidence whenever
an incident occurs |
|
|
Establish a strong trail of evidence whenever
an incident |
|
|
Establish a strong trail of evidence whenever
an incident occurs |
|
|
Involve a lawyer or the police as early as possible whenever you believe that a serious incident has occurred that could result in legal action. |
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
12.2 PERFORM SECURITY COMPLIANCE REVIEWS |
|
|
|
Review regularly the security of your information systems. |
|
|
Review the security of your information
systems by examining |
|
|
Review the security of your information
systems by examining |
|
12.2.1 REVIEW COMPLIANCE WITH SECURITY POLICY |
|
|
|
Review regularly how well your organization
|
|
|
Review regularly how well your organization
|
|
|
Review regularly how well your organization
|
|
|
Review regularly how well your information
systems |
|
|
|