About
Subscribe

Analytix reworks ISO 17799 Information Security Management training

Johannesburg, 30 May 2006

Analytix has reworked its ISO 17799 Information Security Management training to include several new features of the recently improved version of the joint ISO/IEC standard.

This is according to Johan Botha, Managing Director of Analytix.

"The new features of the training take into account the revised ISO 17799:2005, information technology`s security techniques and provides a code of practice for information security management. ISO 17799 integrates the latest developments in the field to maintain it as the international standard code of practice," says Botha.

The modern interconnected e-commerce environment is the main beneficiary of the standard given that information is exposed to a growing number and a wider variety of threats and vulnerabilities.

According to the International Standards Organisation, the revised version of the ISO 17799 standard provides organisations with many enhanced additions and improvements in information security best practice.

Some of these best practices include:

* Better management of security arrangements with external businesses, outsourcing and service providers.
* Enhanced incident handling capability.
* Dealing with problems of patch management, mobile devices, wireless technologies and harmful mobile code via the Internet.
* Improvements in best practice managing human resources.

ISO/IEC 17799:2005 is a code of practice for information security management. It is not a certification standard and was neither designed, nor is it suitable for this purpose. It was followed in November 2005 by the specification standard ISO/IEC 27001, information security management system (ISMS) requirements that can be used for certification.

Botha comments: "The new version addresses the security of information in its widest sense, providing best business practice, guidelines and general principles for implementing, maintaining and managing information security in any organisation, producing and using information in any form."

He continues: "Any organisation has assets, essential to its continuity. Arguably, information in its various forms is the most important asset, be it printed, stored electronically, posted or e-mailed, shown on film or spoken. For most businesses, information security may be essential in maintaining a competitive-edge, cash flow, profitability, legal compliance and commercial image. But many businesses and most non-business organisations may hold information as their only asset. An absence of information security may threaten their integrity and, therefore, their very existence."

According to Botha: "Users of this standard can also demonstrate to business partners, customers and suppliers that they are fit and secure enough to do business with, providing the chance for them to turn their investment in information security into business-enabling opportunities."

Botha concludes: "This revised ISO/IEC 17799 is the most important code of practice for managing information security that has been developed - it establishes a truly international common language for information security for all organisations around the world to engage with each other to do business."

Share

Analytix

Analytix is a training and consulting firm that support organisations to internalise and operationalise best practice frameworks and standards, leading to sustained business improvement. The Analytix solutions portfolio represents a comprehensive collection of professional services, education and other resources in areas such as corporate and IT governance, information security, business continuity management, IT service management and performance management.

Our services are underpinned by a range of de facto industry standards and frameworks, including COBIT, ISO17799, ISO 27001, PAS56 (BS25999), ISO 20000, ITIL and the Balanced Scorecard. Since our inception in 2001, we have assisted over 150 organisations with practical training and advice on the implementation of these leading industry frameworks and standards. Our customers tell us that what separates Analytix from others is our pragmatic approach, based on years of successful operational experience.

Analytix has been awarded Institutional Accreditation status by the Services SETA.

ISO/IEC 17799: 2005 - Code of practice for Information Security Management

ISO 17799, the International Standard for information security management which was enhanced and updated in June 2005, provides a framework for businesses to review and improve the overall effectiveness of their information security.

ISO 27001 (BS7799-2:2002) - A Specification for Information Security Management

The International Standard ISO 27001 (British Standard BS 7799-2:2002, Part 2 of the ISO 17799 Security Standard), has been prepared for business managers and their staff to provide a model for setting up and managing an effective Information Security Management System (ISMS).

Editorial contacts