 On 14th October 2005 the ISO/IEC 27001 standard was published (earlier known as the British BS 7799-2 standard; polish translations PN-I-07799-2:2005),
which is the specification of information safety management system,
for compliance with which certificates are issued.
The ISO/IEC 27001 standard is appropriate for all enterprises,
regardless of the character of their operations,
and contains the requirements,
the fulfillment of which is the basis of granting the ISO 27001 Certificate.
Advantages of implementing the ISO/IEC 27001 system
Using the 27001 system allows determining the requirements of the enterprise in the field of safety,
formulating the information protection and safety policy and selecting the means,
thanks to which information safety can be assured.
The standard supports organizational process in a way,
which makes it possible to rationally improve information safety,
while focusing on the organizational sphere and controlling the increased risk areas,
such as:
- Availability,
meaning ensuring that authorized persons have access to information and assets related with it,
when it is necessary;
- Integrity,
meaning ensuring the precision and completeness of information and its processing methods;
- Confidentiality,
meaning ensuring access to information only to authorized persons;
Availability,
integrity and information confidentiality are of primary significance in order to maintain and improve competitiveness:
- compliance with legal regulations (e.g.
the Act on personal data and its derivatives' protection),
- performance (operations' effectiveness),
- financial liquidity,
- productivity,
- company image.
Adopting the guidelines of the standard gives the ability to decrease the risk of falsifying or even losing information to minimum,
which at the present state of technical development is almost a necessity.
More and more often it is information that is the most valuable means of production,
as restoring it in the case of a loss is an incredibly costly and problematic process,
much more difficult that restoring any other resources.
Additionally,
revealing important information may lead to losing enterprises' competitiveness.
Thus,
information should be of special protection in every enterprise.
|