Arowana has supported organizations in following comprehensive quality systems which can be used in conjunction with the ongoing endeavour on ISO/IEC 27002. The Code of Practice for Information Security Management lists security control objectives and recommends a range of specific security controls for an enterprise.
Arowana believes that organizations that implement ISMS in accordance with the best practice advice in ISO/IEC 27002 are likely to meet the requirements of ISO/IEC 27001 certification but the end value is beyond just certification.
|