NetVision Solution for ISO 27002
ISO 27002 (formerly ISO 17799) is a best practice framework for information security. Many organizations use ISO standards as a way to measure the application of information security in a very subjective field. Others leverage the ISO standard as a way to map specific security solutions to larger control frameworks related to information technology (COBIT) or corporate governance (COSO). That mapping provides a measurable way to prove compliance with governmental and industry regulations that have requirements affecting information technology. Often, the real-world application of IT solutions for compliance with regulations is widely open to interpretation. ISO 27002 has given companies a benchmark framework to work within. In summary, ISO 27002 provides three core values:
- Allows organizations to benchmark their implementation of information security controls.
- Provides a measurable framework with which to meet governmental and industry regulations that are often open to interpretation.
- Enables a multi-regulatory approach of implementing information security controls that meet requirements for multiple regulations.
For more information on ISO 27002, visit the International Organization for Standardization (ISO) web site
[www.iso.org].
NetVision's support for ISO 27002 primarily lies in the identity related sections of the framework (sections 10 & 11).
The table below highlights the primary areas of sections 10 & 11 in which NetVision can directly help implement the
practices recommended by the ISO 27002 framework. Sections shaded in gray are not directly applicable to NetVision solutions.
Please contact NetVision to learn more about how NetVision solutions can be implemented to
support your organization's ISO 27002 standardization efforts!
10 Communications & Operations Management | |
Sections 10.1 - 10.9 |
These requirements do not directly apply to NetVision. |
Section 10.10: |
10.10.1 Audit logs recording user activities, exceptions, and information security events should be produced and kept for an agreed upon period to assist in future investigations and access control monitoring
|
11 Access control | |
Section 11.1: |
11.1.1 An access control policy should be established, documented, and reviewed based on business and security functions |
Section 11.2: |
11.2.1 There should be a formal user registration and deregistration procedure in place for granting and revoking access to all information systems and services
|
Section 11.3: |
11.3.1 Users should be required to follow good security practices in the selection and use of passwords
|
Section 11.4: |
11.4.1 Users should only be provided with access to the services that they have been specifically authorized to use
|
Section 11.5: |
11.5.1 Access to operating systems should be controlled by a secure log-on procedure
|
Section 11.6: |
11.6.1 Access to information and application system functions by users and support personnel should be restricted in accordance with the defined access control policy
|
Section 11.7: |
11.7.1 A formal policy should be in place, and appropriate security measures should be adopted to protect against the risks of using mobile computing and communication facilities
|

