ISMS AND ISO 27001
Beacause data – "information" – is an extremely valuable asset it is crucial that it is kept secure. Effective IT security is critical as much information is now stored, transmitted or processed by IT systems, however without the appropriate processes and procedures the risks can still prevail. Successful businesses recognise the value of an information security policy as part of an Information Security Management System (ISMS).
An ISMS is how a business manages its’ information in a way that ensures that it remains secure (which means available, accessible and suitably protected) and encompasses people and processes as well as technology.. It makes good sense to consider how an ISMS may best work for your organisation and Meritec can help with that.
The international standard ISO27001:2005 provides a framework for how an ISMS should be implemented and for those organisations of a size where it is justifiable compliance with this accreditation is of high value. Meritec holds this accreditation and is well placed to help organisations to understand, prepare for and gain compliance.
However many businesses will rightly feel they cannot justify the time and overheads needed to gain such compliance nor do they necessarily need it in full. For such customers Meritec provides services to help them implement a cutdown Information security system appropriate for their individual needs based on good practice from ISO 27001, this facilitates a cost effective way of making the organisations’ information (including IT systems) more secure.