Development of project documentation for implementation of information security management system in accordance with DSTU ISO/IEC 27001 standard
Context
The transport company implemented a new asset management system, which required the modernization of the server infrastructure and the introduction of new data retention systems. As part of the project implementation, CyHelpers specialists helped the general contractor to form and describe the information security management processes for the new infrastructure and application solution.
The Challenge
It was necessary to develop and implement an information security management system that would comply with international standards and ensure the protection of confidential information, data integrity and availability of information systems. This included creating the appropriate project documentation and ensuring that it complies with the requirements of DSTU ISO/IEC 27001.
The Solution
CyHelpers specialists developed the elements of the information security management system at the enterprise of the transport industry, which included the following stages:
- Analysis of the current state: Carrying out a detailed audit of existing processes and security systems, identifying the main vulnerabilities and risks.
- Development of policies and procedures: Creation of a comprehensive documentation that included policies, procedures, instructions and regulations for the management of information security.
- Development of implementation plan: Determination of the stages of implementation of SAIB, allocation of responsibility and resources, establishment of key performance indicators.
Result
The company received: - Detailed documentation of the information security management system, which complies with the DSTU ISO/IEC 27001 standard, regarding the new business process.
- Докладну документацію системи управління інформаційною безпекою, яка відповідає стандарту ДСТУ ISO/IEC 27001, щодо нового бізнес-процесу.
- Increased resilience to information security threats.
- Increased awareness and qualification of personnel in information security management.
- Improved management of information security risks.