ISO IEC 17799 2000

TRANSLATED INTO PLAIN ENGLISH

Section 6: Personnel Security

FREE DETAILED STANDARD

TO SECTION 5

MAIN MENU TO SECTION 7

ISO 17799 2000 is now OBSOLETE.
Please see
ISO IEC 17799 2005 (27002)!

ISO 17799

ISO17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD

6.1 CONTROL PERSONNEL RECRUITMENT PROCESS

 

Prevent personnel from misusing your information processing facilities.

 

Protect information processing facilities by reducing risk of human error.

 

Protect your information processing facilities by reducing the risk of theft.

 

Protect your information processing facilities by reducing the risk of fraud.

 

Address information security issues during the recruitment process.

 

Make sure that your employment contracts include security provisions.

 

Monitor how well personnel comply with contractual security provisions.

 

Make sure that all new users of information processing
facilities are subjected to a rigorous security screening.

 

Make sure that all new users of information processing
facilities are asked to sign confidentiality agreements.

 

Make sure that new third party users of information processing
facilities are asked to sign confidentiality agreements.

6.1.1 INCLUDE SECURITY IN YOUR JOB DESCRIPTIONS

 

Make sure that job descriptions assign the responsibility
for implementing your information security policy.

 

Make sure that job descriptions assign the responsibility
for maintaining your information security policy.

 

Make sure that job descriptions assign the responsibility
for protecting specific information assets.

 

Make sure that job descriptions assign the responsibility
for performing specific security processes or activities.

6.1.2 CHECK THE BACKGROUNDS OF JOB APPLICANTS

 

Verify the backgrounds of people who apply
for permanent employment with your organization.

 

Check out the character references provided
by people who apply for permanent employment.

 

Verify the professional and academic qualifications
of the people who apply for permanent employment.

 

Confirm the personal identity of people
who apply for permanent employment.

 

Perform credit checks for all personnel who will
have access to information processing facilities.

 

Perform periodic credit checks for all personnel
who will have access to information processing
facilities and have considerable authority.

 

Verify the backgrounds of all contractors who will
have access to your information processing facilities.

 

Verify the backgrounds of all temporary employees who
will have access to information processing facilities.

 

Make sure that contracts with personnel recruitment agencies
specify the personnel screening requirements that must be met.

 

Make sure that your contracts with personnel recruitment agencies specify the reporting procedures that should be followed whenever background checks reveal a problem.

 

Make sure that new and inexperienced staff, who have
access to information processing facilities, are supervised.

 

Make sure that your managers evaluate the
supervision of all new and inexperienced staff.

 

Make sure that managers review the work of all staff
who have access to information processing facilities.

 

Make sure that managers monitor how personal
problems can influence the work of staff members.

 

Make sure that managers monitor how personal financial
problems can influence the work of their staff members.

 

Make sure that managers monitor how personal lifestyle
problems can influence the work of their staff members.

 

Make sure that your managers monitor how personal
psychological problems can influence the work of staff.

 

Make sure that your managers comply with the legal
rules and regulations that govern the collection and
use of personal information.

6.1.3 USE CONFIDENTIALITY OR NON‑DISCLOSURE AGREEMENTS

 

Make sure that all new employees sign confidentiality
or non‑disclosure agreements before they are given
access to information processing facilities.

 

Make sure that confidentiality and non‑disclosure agreements
are reviewed whenever the terms of employment change.

6.1.4 USE EMPLOYMENT CONTRACTS TO PROTECT INFORMATION

 

Make sure that your employment contracts define
your
employee’s information security responsibilities.

 

Make sure that your employment contracts specify the actions that you will take if employees disregard your information security requirements.

 

Make sure that your employment contracts
clarify all copyrights and responsibilities.

 

Make sure that your employment contracts clarify
all data protection rights and responsibilities.

 

Make sure that employment contracts define employees’
information management responsibilities.

 

Make sure that your employment contracts define your
employees’ information classification responsibilities.

 

Make sure that your employment contracts make it clear
that the employees’ information security responsibilities
also apply outside of normal working hours.

 

Make sure that your employment contracts make it clear
that the employee’s information security responsibilities
also apply outside of your organization’s work premises.

 

Make sure that your employment contracts make it clear
that employee’s information security responsibilities will
continue for a specified time period after the employee
leaves your organization.

ISO17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD

6.2 PROVIDE INFORMATION SECURITY TRAINING

 

Make sure that your users are aware of
information security threats and concerns.

 

Make sure that users are capable of
applying your information security policy.

 

Make sure that you teach users how
to apply your security procedures.

 

Make sure that you teach your users how to use
your information processing services and facilities.

 

Make sure that you teach your users how to
minimize possible information security risks.

6.2.1 CONTROL YOUR INFORMATION SECURITY TRAINING

 

Teach employees and other users about your security
requirements before you allow them to have access
to your organization’s information and services.

 

Teach employees and other users about their legal
responsibilities before you allow them to have
access
to your organization’s information and services.

 

Teach employees and other users about your business
controls before you allow them to have access to your
organization’s information and services.

 

Teach employees and other users how to use your information
processing services and facilities before you
allow them
to have access to those facilities and services.

ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD

6.3 RESPOND TO INFORMATION SECURITY INCIDENTS

 

Make sure that your organization tries to minimize
the damage caused by information security incidents.

 

Make sure that people are required to report all security incidents.

 

Make sure that people know how to report security incidents.

 

Make sure that people know how to use reporting procedures.

 

Make sure that people report information security incidents.

 

Monitor your information security incidents.

 

Make sure that your organization learns
from its information security incidents.

 

Set up an official disciplinary process that you can use
to deal with people who commit security breaches.

6.3.1 REPORT INFORMATION SECURITY INCIDENTS

 

Make sure that security incidents are reported to management.

 

Develop a formal incident reporting procedure.

 

Make people aware of your reporting procedure.

 

Set up a feedback mechanism to ensure that incident
reporters learn about how an incident was handled.

 

Make sure that you use reported incidents to teach people
about security incidents and how they should be handled.

 

Develop a formal incident response procedure.

6.3.2 REPORT SECURITY THREATS AND WEAKNESSES

 

Make sure that people are required to report all suspected
threats to the security of information services and systems.

 

Make sure that people report all information security threats.

 

Make sure that people are required to report all
observed weaknesses in the security of your
information services and systems.

 

Make sure that people report all
information security weaknesses.

 

Make sure that people have been told not to try
to prove or test weaknesses in the security of
your information services and systems.

6.3.3 CONTROL YOUR SOFTWARE MALFUNCTIONS

 

Develop a procedure for reporting software malfunctions.

 

Make sure that your malfunction reporting procedure expects
people to document the problem and to record screen messages.

 

Make sure that your software malfunction reporting procedure
expects people to report malfunctions without delay.

 

Make sure that your reporting procedure ensures that the
malfunction is reported to the information security manager.

 

Develop a procedure for responding to software malfunctions.

 

Make sure that software malfunction response procedure
ensures that the malfunctioning computer is isolated.

 

Make sure that your response procedure ensures that
use of the malfunctioning computer will stop immediately.

 

Make sure that your software malfunction response procedure
ensures that the malfunctioning computer’s diskettes will not
be transferred to other computers.

 

Make sure that your software malfunction response procedure ensures that only authorized experts are allowed to remove suspect software.

 

Make sure that your malfunction response procedure ensures that
only authorized experts are allowed to carry out the recovery process.

6.3.4 LEARN FROM YOUR SECURITY INCIDENTS

 

Develop mechanisms that you can use to learn
about your information security incidents.

 

Monitor and quantify the types of security incidents.

 

Monitor and quantify the costs of security incidents.

 

Make sure that you can identify recurring security incidents.

 

Make sure that you can identify high impact security incidents.

 

Make sure that you use what you learn about your
security incidents to improve your information security.

 

Make sure that you use what you learn about security
incidents to improve your information security policy.

6.3.5 DEVELOP A DISCIPLINARY PROCESS

 

Develop a formal process that you can use
to discipline people who have violated your
information security policies and procedures.

 

Make sure that your disciplinary process ensures
that people who are suspected of committing serious
security breaches are treated fairly and correctly.

 

Ensure that your disciplinary process acts as a deterrent.

ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD

TO SECTION 5

MAIN MENU TO SECTION 7
OTHER ISO 17799 2000 INFORMATION SECURITY WEB PAGES

ISO ISO 17799 2000 - Section 3: Security Policy

ISO 17799 2000 - Section 4: Organizational Structure

ISO 17799 2000 - Section 5: Asset Classification and Control

ISO 17799 2000 - Section 7: Physical and Environmental Security

ISO 17799 2000 - Section 8: Communications and Operations

ISO 17799 2000 - Section 9: Access Control Management

ISO 17799 2000 - Section 10: Systems Development and Maintenance

ISO 17799 2000 - Section 11: Business Continuity Management

ISO 17799 2000 - Section 12: Compliance Management

ISO 17799 2005 (27002 2005) INFORMATION SECURITY WEB PAGES

Introduction to ISO 17799 2005 (27002) Information Security Standard

Overview of the ISO 17799 2005 (27002) Information Security Standard

ISO 17799 2005 (27002) Information Security Management Definitions

ISO 17799 2005 (27002) Security Standard Translated into Plain English

List of ISO 17799 2005 (27002) Information Security Control Objectives

ISO 17799 2005 (27002) Information Security Management Audit Tool

ISO 27001 2005 INFORMATION SECURITY WEB PAGES

Introduction to the ISO 27001 2005 Security Standard

Brief Comparison of ISO 27001 2005 and ISO 27002 2005

Overview of ISO 27001 2005 Information Security Standard

ISO 27001 2005 Security Standard Translated into Plain English

ISO 27001 Information Security Management Gap Analysis Tool

ISO 27001 2005 Standard in Plain English - Table of Contents

ISO 27001 AND 27002 ARE INFORMATION SECURITY MANAGEMENT STANDARDS

ISO 17799

ISO 17799  NAVIGATION GUIDE

       
Home Page Table of Contents Alphabetical Index Site Map
       
How to Order Our Products Our Prices Our Guarantee
       
 

ISO 17799

 
CONTACT INFORMATION
 
Praxiom Research Group Limited
9619 - 100A Street, Edmonton,
Alberta, T5K 0V7, Canada
Phone: (780)461-4514
Fax: (780)463-6034

info@praxiom.com
 

Legal Restrictions on the Use of this Page
Thank you for visiting this page. You are, of course, welcome to view our
 material as often as you wish, free of charge. And as long as you keep intact
 all copyright notices, you are also welcome to print or make one copy of this
 page for your own personal, noncommercial, home use.   But, you are not
 legally authorized to print or produce additional copies, or to copy and paste
 any of our material onto another web site.  If you would like to purchase our
 material, please contact our Sales Desk. Our staff would be very pleased to
 take your order or to answer any questions you might have.

Copyright © 2005 - 2007 by Praxiom Research Group Limited. All Rights Reserved.

Disclaimer and Limitation of Liability
The publisher and authors have used their best efforts in designing and
  developing this electronic publication. We make no representation or warranties
  with respect to accuracy or completeness of the contents of this publication and
  specifically disclaim any implied warranties or merchantability or fitness for any
  particular purpose and shall in no event be liable for any loss of profit or any
  other commercial damage, including but not limited to special, incidental,
  consequential, or other damages.

ISO 17799

This web page was updated on October 2, 2007

On the Web since May 25, 1997