ISO IEC 17799 2000TRANSLATED INTO PLAIN ENGLISHSection 5: Asset Classification and ControlFREE DETAILED STANDARD |
||
| MAIN MENU | TO SECTION 6 | |
|
ISO
17799 2000 is now OBSOLETE. |
||
![]()
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
5.1 MAKE INFORMATION ASSET OWNERS ACCOUNTABLE |
|
|
|
Select an owner for each major information asset. |
|
|
Make sure that asset owners have been asked to protect their assets. |
|
|
Make sure that asset owners have been asked to implement controls. |
|
|
Make sure that asset owners have been asked to maintain controls. |
|
|
Hold asset owners accountable for the security of information assets. |
|
5.1.1 COMPILE AN INVENTORY OF ALL INFORMATION ASSETS |
|
|
|
Identify all of your information assets. |
|
|
Compile an inventory of all information assets. |
|
|
Compile an inventory of all databases and date files. |
|
|
Compile an inventory of all system documentation. |
|
|
Compile an inventory of all user manuals. |
|
|
Compile an inventory of all procedures. |
|
|
Compile an inventory of all training materials. |
|
|
Compile an inventory of all continuity plans. |
|
|
Compile an inventory of all fallback plans. |
|
|
Compile an inventory of all archived information. |
|
|
Compile an inventory of all software assets. |
|
|
Compile an inventory of all application software. |
|
|
Compile an inventory of all system software. |
|
|
Compile an inventory of all development tools. |
|
|
Compile
an inventory of all the physical |
|
|
Compile an inventory of all computer equipment. |
|
|
Compile an inventory of all processors. |
|
|
Compile an inventory of all monitors. |
|
|
Compile an inventory of all laptops. |
|
|
Compile an inventory of all modems. |
|
|
Compile an inventory of all routers. |
|
|
Compile an inventory of all PABXs. |
|
|
Compile an inventory of all telephones. |
|
|
Compile an inventory of all fax machines. |
|
|
Compile an inventory of all answering machines. |
|
|
Compile an inventory of all magnetic media. |
|
|
Compile an inventory of all tapes and disks. |
|
|
Compile an inventory of all power supplies. |
|
|
Compile an inventory of all air conditioning units. |
|
|
Compile an inventory of all the services |
|
|
Compile an inventory of all computing services. |
|
|
Compile an inventory of all communication services. |
|
|
Compile an inventory of all utility services. |
|
|
Define levels of protection for your information assets. |
|
|
Assign a security classification to all information assets. |
|
|
Classify all information assets according to
how |
|
|
Make sure
that your classification system |
|
|
Make sure that your classification system clearly |
|
|
Make sure
that you provide a higher level of protection |
|
ISO17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
5.2 USE AN INFORMATION CLASSIFICATION SYSTEM |
|
|
|
Use a classification system to protect information. |
|
|
Define a set of security levels for your information. |
|
|
Make sure that your classification system specifies how information should be protected and handled at each security level. |
|
5.2.1 DEVELOP INFORMATION CLASSIFICATION GUIDELINES |
|
|
|
Develop guidelines for classifying information. |
|
|
Make sure
that your classification guidelines allow you to |
|
|
Make sure
that your information classification system |
|
|
Make sure
that your information classification system restricts |
|
|
Give the
responsibility for classifying information |
|
|
Give the responsibility for reviewing your
information |
|
|
Make sure
that your personnel understand how |
|
|
Make sure that you label information according to how valuable it is. |
|
|
Make sure that you label information according to how sensitive it is. |
|
|
Make sure that you label information according to how critical it is. |
|
|
Classify all information according to how
critical |
|
|
Make sure
that your most critical or sensitive information receives |
|
|
Apply your classification system to documents. |
|
|
Apply your classification system to data records. |
|
|
Apply your classification system to data files. |
|
|
Apply your classification system to disks. |
|
5.2.2 USE INFORMATION HANDLING AND LABELING PROCEDURES |
|
|
|
Develop information handling procedures for
|
|
|
Develop a copying procedure for each information security classification. |
|
|
Develop a storage procedure for each information security classification. |
|
|
Develop a transmission procedure for each security classification. |
|
|
Develop a snail mail procedure for each security classification. |
|
|
Develop an email procedure for each security classification. |
|
|
Develop a fax procedure for each security classification. |
|
|
Develop a telephone procedure for each security classification. |
|
|
Develop a mobile phone procedure for each security classification. |
|
|
Develop a voice mail procedure for each security classification. |
|
|
Develop an answering machine procedure |
|
|
Develop a face‑to‑face communications
procedure |
|
|
Develop an
information destruction procedure |
|
|
Develop an output labeling procedures |
|
|
Make sure that your security labeling
procedures expect |
|
|
Make sure that your security labeling
procedures expect |
|
|
Make sure that your security labeling
procedures expect |
|
|
Make sure that your security labeling
procedures |
|
|
Make sure that your security labeling
procedures |
|
|
Make sure that your security labeling |
|
|
Make sure that security labeling procedures
|
|
|
Make sure that security labeling procedures
|
|
|
Make sure that security labeling procedures
|
|
|
Make sure that security labeling procedures
|
|
ISO17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
![]()

| Home Page | Table of Contents | Alphabetical Index | Site Map |
| How to Order | Our Products | Our Prices | Our Guarantee |
![]()
| CONTACT INFORMATION |
| Praxiom Research Group Limited 9619 - 100A Street, Edmonton, Alberta, T5K 0V7, Canada Phone: (780)461-4514 Fax: (780)463-6034 info@praxiom.com |
Legal
Restrictions on the Use of this Page
Thank you
for visiting this page. You are, of course, welcome to view our
material as often as you wish, free of charge. And as long as you keep
intact
all copyright notices, you are also welcome to print or make one copy of
this
page for your own personal, noncommercial, home use. But, you
are not
legally authorized to print or produce additional copies, or to copy and
paste
any of our material onto another web site. If you would like to
purchase our
material, please contact our Sales Desk. Our staff would be very pleased to
take your order or to answer any questions you might have.
Copyright © 2005 - 2007 by Praxiom Research Group Limited. All Rights Reserved.
Disclaimer
and Limitation of Liability
The
publisher and authors have used their best efforts in designing and
developing this electronic publication. We make no representation or
warranties
with respect to accuracy or completeness of the contents of
this publication and
specifically disclaim any implied warranties or
merchantability or fitness for any
particular purpose and shall in no
event be liable for any loss of profit or any
other commercial damage,
including but not limited to special, incidental,
consequential, or
other damages.
![]()
This web page was updated on October 2, 2007
On the Web since May 25, 1997