ISO IEC 17799 2000TRANSLATED INTO PLAIN ENGLISHSection 6: Personnel SecurityFREE DETAILED STANDARD |
||
| MAIN MENU | TO SECTION 7 | |
|
ISO
17799 2000 is now OBSOLETE. |
||
![]()
|
ISO17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
6.1 CONTROL PERSONNEL RECRUITMENT PROCESS |
|
|
|
Prevent personnel from misusing your information processing facilities. |
|
|
Protect information processing facilities by reducing risk of human error. |
|
|
Protect your information processing facilities by reducing the risk of theft. |
|
|
Protect your information processing facilities by reducing the risk of fraud. |
|
|
Address information security issues during the recruitment process. |
|
|
Make sure that your employment contracts include security provisions. |
|
|
Monitor how well personnel comply with contractual security provisions. |
|
|
Make sure that all new users of information
processing |
|
|
Make sure that all new users of information
processing |
|
|
Make sure that new third party users of
information processing |
|
6.1.1 INCLUDE SECURITY IN YOUR JOB DESCRIPTIONS |
|
|
|
Make sure that job descriptions assign the
responsibility |
|
|
Make sure that job descriptions assign the
responsibility |
|
|
Make sure that job descriptions assign the
responsibility |
|
|
Make sure that job descriptions assign the
responsibility |
|
6.1.2 CHECK THE BACKGROUNDS OF JOB APPLICANTS |
|
|
|
Verify the backgrounds of people who apply |
|
|
Check out the character references provided
|
|
|
Verify the professional and academic
qualifications |
|
|
Confirm the personal identity of people |
|
|
Perform credit checks for all personnel who
will |
|
|
Perform periodic credit checks for all
personnel |
|
|
Verify the backgrounds of all contractors who
will |
|
|
Verify the backgrounds of all temporary
employees who |
|
|
Make sure that contracts with personnel
recruitment agencies |
|
|
Make sure that your contracts with personnel recruitment agencies specify the reporting procedures that should be followed whenever background checks reveal a problem. |
|
|
Make sure that new and inexperienced staff,
who have |
|
|
Make sure that your managers evaluate the |
|
|
Make sure that managers review the work of all
staff |
|
|
Make sure that managers monitor how personal
|
|
|
Make sure that managers monitor how personal
financial |
|
|
Make sure that managers monitor how personal
lifestyle |
|
|
Make sure that your managers monitor how
personal |
|
|
Make sure that your managers comply with the
legal |
|
6.1.3 USE CONFIDENTIALITY OR NON‑DISCLOSURE AGREEMENTS |
|
|
|
Make sure that all new employees sign
confidentiality |
|
|
Make sure that confidentiality and
non‑disclosure agreements |
|
6.1.4 USE EMPLOYMENT CONTRACTS TO PROTECT INFORMATION |
|
|
|
Make sure that
your employment contracts define |
|
|
Make sure that your employment contracts specify the actions that you will take if employees disregard your information security requirements. |
|
|
Make sure that your employment contracts |
|
|
Make sure that your employment contracts
clarify |
|
|
Make sure that employment contracts define
employees’ |
|
|
Make sure that your employment contracts
define your |
|
|
Make sure that
your employment contracts make it clear |
|
|
Make sure that
your employment contracts make it clear |
|
|
Make sure that
your employment contracts make it clear |
|
ISO17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
6.2 PROVIDE INFORMATION SECURITY TRAINING |
|
|
|
Make sure that
your users are aware of |
|
|
Make sure that
users are capable of |
|
|
Make sure that you teach users how |
|
|
Make sure that
you teach your users how to use |
|
|
Make sure that
you teach your users how to |
|
6.2.1 CONTROL YOUR INFORMATION SECURITY TRAINING |
|
|
|
Teach employees and
other users about your security |
|
|
Teach
employees and other users about their legal |
|
|
Teach employees and
other users about your business |
|
|
Teach employees and other users how to use
your information |
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
|
6.3 RESPOND TO INFORMATION SECURITY INCIDENTS |
|
|
|
Make sure that your organization tries to
minimize |
|
|
Make sure that people are required to report all security incidents. |
|
|
Make sure that people know how to report security incidents. |
|
|
Make sure that people know how to use reporting procedures. |
|
|
Make sure that people report information security incidents. |
|
|
Monitor your information security incidents. |
|
|
Make sure that your organization learns |
|
|
Set up an official
disciplinary process that you can use |
|
6.3.1 REPORT INFORMATION SECURITY INCIDENTS |
|
|
|
Make sure that security incidents are reported to management. |
|
|
Develop a formal incident reporting procedure. |
|
|
Make people aware of your reporting procedure. |
|
|
Set up a feedback
mechanism to ensure that incident |
|
|
Make sure that
you use reported incidents to teach people |
|
|
Develop a formal incident response procedure. |
|
6.3.2 REPORT SECURITY THREATS AND WEAKNESSES |
|
|
|
Make sure that people are required to report
all suspected |
|
|
Make sure that people report all information security threats. |
|
|
Make sure that people are required to report
all |
|
|
Make sure that people report all |
|
|
Make sure that
people have been told not to try |
|
6.3.3 CONTROL YOUR SOFTWARE MALFUNCTIONS |
|
|
|
Develop a procedure for reporting software malfunctions. |
|
|
Make sure that your malfunction reporting
procedure expects |
|
|
Make sure that your software malfunction
reporting procedure |
|
|
Make sure that your reporting procedure
ensures that the |
|
|
Develop a procedure for responding to software malfunctions. |
|
|
Make sure that software malfunction response
procedure |
|
|
Make sure that your response procedure ensures
that |
|
|
Make sure that your software malfunction
response procedure |
|
|
Make sure that your software malfunction response procedure ensures that only authorized experts are allowed to remove suspect software. |
|
|
Make sure that your malfunction response
procedure ensures that |
|
6.3.4 LEARN FROM YOUR SECURITY INCIDENTS |
|
|
|
Develop mechanisms that you can use to learn
|
|
|
Monitor and quantify the types of security incidents. |
|
|
Monitor and quantify the costs of security incidents. |
|
|
Make sure that you can identify recurring security incidents. |
|
|
Make sure that you can identify high impact security incidents. |
|
|
Make sure that you use what you learn about
your |
|
|
Make sure that you use what you learn about
security |
|
6.3.5 DEVELOP A DISCIPLINARY PROCESS |
|
|
|
Develop a formal process that you can use |
|
|
Make sure that your disciplinary process
ensures |
|
|
Ensure that your disciplinary process acts as a deterrent. |
|
ISO 17799 IS AN INFORMATION SECURITY MANAGEMENT STANDARD |
|
![]()

| Home Page | Table of Contents | Alphabetical Index | Site Map |
| How to Order | Our Products | Our Prices | Our Guarantee |
![]()
| CONTACT INFORMATION |
| Praxiom Research Group Limited 9619 - 100A Street, Edmonton, Alberta, T5K 0V7, Canada Phone: (780)461-4514 Fax: (780)463-6034 info@praxiom.com |
Legal
Restrictions on the Use of this Page
Thank you
for visiting this page. You are, of course, welcome to view our
material as often as you wish, free of charge. And as long as you keep
intact
all copyright notices, you are also welcome to print or make one copy of
this
page for your own personal, noncommercial, home use. But, you
are not
legally authorized to print or produce additional copies, or to copy and
paste
any of our material onto another web site. If you would like to
purchase our
material, please contact our Sales Desk. Our staff would be very pleased to
take your order or to answer any questions you might have.
Copyright © 2005 - 2007 by Praxiom Research Group Limited. All Rights Reserved.
Disclaimer
and Limitation of Liability
The
publisher and authors have used their best efforts in designing and
developing this electronic publication. We make no representation or
warranties
with respect to accuracy or completeness of the contents of
this publication and
specifically disclaim any implied warranties or
merchantability or fitness for any
particular purpose and shall in no
event be liable for any loss of profit or any
other commercial damage,
including but not limited to special, incidental,
consequential, or
other damages.
![]()
This web page was updated on October 2, 2007
On the Web since May 25, 1997