Home > Ask the Security Experts > Expert Archive: Security Management Questions & Answers > Should ISO 17799 play a role in risk assessment?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Should ISO 17799 play a role in risk assessment?

Mike Rothman, past SearchSecurity.com expert EXPERT RESPONSE FROM: Mike Rothman, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 28 June 2007
What's the best procedure for conducting a risk assessment for an organization such as a drug research and trial company? Should ISO 17799 play a role by default?

>
There is a pretty accepted process for doing a risk assessment. First, figure out what needs to be protected and see if it's secure. It's not exactly that simple, but it's not overly complicated either.

A pharmaceutical company has a lot at risk since pretty much all its intellectual property is in the form of electronically stored compounds and trial data, which is very valuable. For instance, consider a blockbuster drug that has the potential to be a multi-billion-dollar business. Clearly the focus of the assessment should be on protecting those kinds of assets.

Once polices are to make sure they adequately set the stage to protect critical assets, it's time to see whether the rubber meets the road by conducting some vulnerability testing. I'm a fan of both electronic testing, as well as human testing. So perform automated scans (to find obvious stuff) and use penetration testing tools (for both networks/systems and applications) to view your environment as a hacker sees it.

Periodically an organization should administer a manual pen test, where a skilled attacker uses social engineering techniques and looks for logic flaws in an environment. Most regulations require a formal "assessment" at least once per year -- so these are probably already happening.

Relative to ISO 17799 and its successor, ISO 27001, those are relatively comprehensive frameworks laying out all of the things (policies and procedures) that can be protected, as opposed to all of the assets that should be protected.

If you need a list of things to "assess," one of the ISO frameworks can be used as a starting point. But I would consider it a default if it's already understood what's protected and how the attackers can get the data.

For more information:

  • Learn how ISO 17799 can help security professionals perform partner and service provider due diligence.
  • Learn the five steps behind making organizational risk management work in your enterprise.


  • BROWSE BY TAG
    Expert Archive: Security Management,   Security Audit, Compliance and Standards,   ISO 17799,   Enterprise Risk Management: Metrics and Assessments,   Information Security Management,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Expert Archive: Security Management
    What is the GISP certification and how does it compare to the CISSP certification?
    Using a QSA to write up a PCI DSS report on compliance (ROC)
    How can gap analysis be applied to the security SDLC?
    Comparing cheap security products and appliances to costly appliances
    What are some tips on protecting my security budget in a poor economy?
    What value do research firms provide to their subscribing enterprises?
    What certificate offers the best ROI for an IT project manager?
    Is insider activity or outsider activity a bigger enterprise threat?
    How does information security prevent fraud in the enterprise?
    Differences between an SAS 70 data center and a Tier III data center

    ISO 17799
    Tony Spinelli: Prioritize Information Security over Compliance
    How to write a risk methodology that blends business, security needs
    IT auditing applications and tools for ISO 27002 certification
    Security survey finds increase in security standards adoption
    Mix of Frameworks and GRC Satisfy Compliance Overlaps
    GRC: Over-Hyped or Legit?
    Is the Orange Book still relevant for assessing security controls?
    How do ISO 17799 and SAS 70 differ?
    How to apply ISO 27002 to PCI DSS compliance
    How to migrate from SAS 70 to ISO 27001

    Enterprise Risk Management: Metrics and Assessments
    How to avoid Internet liability lawsuits
    Bruce Jones: Report Security and Risk Metrics in a Business-Friendly Way
    Bernie Rominski: Communicate Effectively with Management about Risk
    Best Policy and Risk Management Products
    Monitoring program data and internal controls for risk management
    Risk management strategy for an information technology solution provider
    Align your data protection efforts with GRC
    The basics of enterprise GRC project management
    RSA council addresses growing security risks in the cloud
    How to write a risk methodology that blends business, security needs
    Enterprise Risk Management: Metrics and Assessments Research

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts