ISO SYSTEM

ICMC (International Certification Management Center Co., Ltd.)

ISO 27001 Information Security

ISO 27001 (Information Security Management System)


Overview

It is the most prestigious certification in the field of information protection with international standard information protection certification. Originally the British Standard (BS), it was BS7799, but was promoted to the ISO standard in November 2005. The scope of certification evaluates and awards certification for how well it plans, implements, inspects, and improves 133 items in 11 areas of information protection management, including information protection policy, communication and operation, access control, and response to information protection accidents.




ISO 27001 Background

The latest hardware and security software are being introduced to protect important IT services and information from various threats, but they provide a fragmentary solution, not a fundamental solution.
In addition, many global companies are implementing ISMS (Information Security Management System) by establishing appropriate security procedures for security threats and the appropriateness of their security policies and practices. This is the beginning of the introduction of IS0/IEC 27001, which is recognized as an official ISMS.




Composition of ISO 27001

ISO/IEC 27001 consists of basic requirements for ISMS, Control Objectives, and Controls. ISO/IEC 27001 certification is issued by examining whether the organization's ISMS meets the basic requirements required by this specification and is implementing control measures.




ISO 27001 Evaluation Items

NO Title Detailed evaluation items
1
A.5 Security Policy 2
2 A.6 Organization of Information Security 11
3 A.7 Asset management 5
4 A.8 Human Resource Security 9
5 A.9 Physical and Environmental Security 13
6 A.10 Communications&Operations Management 32
7 A.11 Access Control 25
8 A.12 Information Systems Acquisition, Development&Maintenance 16
9 A.13 Information security incident management 5
10 A.14 Business continuity management 5
11 A.15 Regulatory compliance 10



Effectiveness of introducing ISO 27001

ISO 27001 is the only global standard in the world and is configured to establish and operate standards in any country or organization. Therefore, if the organization's information protection management system is established and operated based on the ISO 27001 standard requirements, the effectiveness of the organization's information protection management system will be recognized consistently anywhere in the world.



ICMC (International Certification Management Center)
Global/Domestic RA Consulting & GMP(ISO) Internal Auditor Training

ICMC has been working tirelessly to become a customer-satisfying company by securing experienced and excellent RA consultants and audit instructors as a specialized institution for global/domestic RA consulting & GMP(ISO) internal auditor training for more than 25 years. ICMC will provide consulting services to enable the introduction of an internationally recognized system through skilled professionals. In addition, ICMC will provide training services to respond to domestic GMP and international ISO audits, strengthen practical competencies, and acquire internal audit skills. Through this, through the implementation of the global system, the safety, reliability and quality of products can be improved and international competitiveness can be secured. ICMC provides customized consulting services for global system establishment in the shortest period and minimum cost, as well as education to establish the overall concept and operation method of domestic GMP and global ISO, and will become an essential partner for entering the global market.