| confidentiality: has been defined by the ISO as
"ensuring that information is accessible only to those authorised to have access"
and is one of the cornerstones of Information Security
integrity: refers to the safeguarding of the accuracy and completeness
of data and processing methods by protecting against unauthorised modification
availability: is ensuring that authorised users have access to data and associated access as and when required
|
 |
the existence of a risk-based information security management policy,
implemented through an ISMS is clear evidence that the organisation has taken the necessary and appropriate steps to protect their business assets
conformance to ISO17799 provides company directors with a systematic, risk assessment based approach
to meeting their responsibilities under the Combined Code on Corporate Governance, the Turnbull Guidance and
Sarbanes-Oxley and the wide range of interlocking data protection and privacy legislation to which they are subject
|