NRS Nepal
  • Home
  • About
    • History
    • Our Team
    • Alliances
    • Client's Feedbacks
    • Intern's Testimonials
  • Services
    • Human Resource
    • Education & Training
    • Consultation Services
    • Research & Development
    • Accounting & Financial
    • Management Consulting
    • ISO Standard Certification
      • ISO 9001 Certification
      • ISO 14001 Certification
      • ISO 22000 Certification
      • ISO 15189 Certification
      • ISO 27701 Certification
      • ISO 45001 Certification
      • ISO 27001 Certification
      • Other Certifications
    • Strategy & Operation
    • Boutique Consulting
    • Technical Consulting
  • Internship
  • Corporate Events
  • Support Startup
  • Career
  • Blog
  • Contact

Process for IS0 27001: 2013 (Information Security Management System) Certification

June 23, 2019    |    NRS Admin    |    Management Consultancy ISO Consulting Service ISO Certification Service Consultancy Services
Process for IS0 27001: 2013 (Information Security Management System) Certification

IS0 27001: 2013 -INFORMATION SECURITY MANAGEMENT SYSTEM
Information Security Management System formally specifies a management system that helps organizations identify, design, and implement the information security controls that are necessary to ensure the confidentiality, integrity and availability of its information assets. ISO 27001:2013 certifications validates Companies capabilities in developing and maintaining state-of-art Data Center facility and Network Infrastructure.


ISO 27001 standard details all that is needed to establish, operate, maintain, and review a documented Information Security Management System (ISMS) through security controls tailored to the requirements of an organization. It encompasses all manner of organizations from businesses to government agencies to nonprofit groups.


Information Security Management System is that part of the overall management system, based on a business risk approach, to establish, implement, operate, monitor, review, maintain and improve information security and always follows Plan-Do-Check-Act methodology.

The Plan phase is about designing the ISMS, assessing information security risks and selecting appropriate controls.
The Do phase involves implementing and operating the controls.
The Check phase objective is to review and evaluate the performance (efficiency and effectiveness) of the ISMS.
In the Act phase, changes are made where necessary to bring the ISMS back to peak performance
By implementing ISMS through ISO 27001, Companies can ensure that it is managing its information security processes in a structured manner and that it can customize its ISMS to its business needs.

Specifically, ISO 27001- Information Security Management System is used within an organization to:
• Identify security requirements and frame objectives.
• Ensure that the organization’s security objectives are fulfilled.
• Ensure that security risks are economically managed.
• Ensure that applicable laws and regulations are complied with.
• Determine the status of information security management activities.
• Supply information on information security policies, directives, standards and procedures to other organizations.
• Provide information on information security to customers.

 

Methodology

Details of Key Roadmap Activities for ISMS Implementation
PHASE I: ISO 27001:2013 ISMS AWARENESS TRAINING PROGRAM
Purpose The purpose of this step is creating a familiarization across a large group of people in the Organization on the ISMS Standard and sensitizes the Organization on the Standard implementation aspects and requirements.

It also serves to motivate key people in the Organization to appreciate the benefits of ISMS for driving process excellence in the Organization and prepares champions and leaders who can contribute to the initiative in the future roadmap.

 

Objectives

• Familiarize people on ISMS Standard
• Sensitize Organization on the implementation aspects and expectations of the model
• Create core group of champions & leaders to lead the initiative

 

Activities 

• Identify the Core ISMS Team
• Provide training on ISO 27001:2013

 

Deliverables

• Provide training for the Core Team
• Training Materials for the Core ISMS Team
NRS Responsibilities • Provide master copy of courseware
• Faculty with Extensive Experience in the domain
• Conduct the Internal Auditor Training program

 

Client Responsibilities

• Identify participants for the Training
• Provide facility to conduct the training program
• Material for Training need shall be organized

 

PHASE II: DIAGNOSTIC STUDY- IMPLEMENTATION, REVIEW & ACTION PLANNING
Purpose The purpose of this activity is to perform the base-lining activity
to get a snapshot of the organization’s current strengths and weakness. This information gathered from the baseline will then be used to initiate development of the strategic action plan that will provide guidance and direction to the process improvement program

To accomplish base-lining activities require a significant amount of coordination of people, data, facilities, training activities and support services. Hence, it is recommended that some time is spent on planning the initiative, especially because this activity involves drawing out the future implementation action plan.

 

Objectives

Gather a snapshot of actual strengths and weakness in the Information Security related areas vis-a vis Control objectives as per ISO 27001:2013 Controls

 

Activities

• Assess the conformance of documented processes to ISO 27001: 2013 standard
• Understand Organizations requirements and improvement goals
• Identify improvement opportunities
• Assess the degree of implementation and institutionalization of these processes
• Brief senior management on the Assessment findings and present an action plan (presentation/workshop, as appropriate)

 

Deliverables

• An assessment findings report giving the Security Controls and their profile (functional characteristics, strengths, weaknesses) and Improvement opportunities (Gaps with respect to ISO 27001: 2013 standard)
• Identify Key metrics on which improvement can be committed

 

Nepal Realistic Solution Responsibilities

• Administer the capability questionnaire.
• Conduct structured interviews & Analyze responses
• Review documentation & assess conformance to ISO 27001:2013 standard
• Prepare the assessment report
• Brief senior management
• Facilitate production of an initial Action Plan

 

Client Responsibilities

• Identify, assign and schedule appropriate resources for answering the questionnaire, and for interviews where appropriate
• Make all requested documents available
• Create an Action Plan, with help from Nepal Realistic Solution

 

PHASE III: EXECUTION POLICY/ PROCEDURE DESIGN, DEVELOPMENT & FACILITATION
Purpose The purpose of this step is to develop solutions for the procedure/policy definition and implementation gaps identified during the organizational base-lining activity. The solutions for the procedures/ policies to be improved have to be defined, documented and must enable the achievement of business objective.


The solution selected should be compatible with the organization’s culture so that it will be readily accepted and institutionalized. To enable institutionalization in an accelerated manner, the needed supporting elements [policy, procedure, template, checklist, guidelines, exceptions, roles & responsibilities must be clearly defined for each of the process of ISMS.

 

Objectives

• Investigate alternative solutions to procedure/policy issues
• discovered
• Refine the existing procedures and policies to eliminate errors and reduce variation

 

Activities

• Conduct Risk assessment & create Risk treatment plans
• Refine existing procedures/policies as identified in the Action Plan
• Create Statement of Applicability
• Create ISMS manual
• Identify process stakeholders and understand their needs
• Determine the current process, boundary and context
• Define the effectiveness measures

 

Deliverables

• Fully developed and documented ISMS policies & procedures aligned
• to the business needs, based on ISMS best practices.
• Effectiveness measures
• Mandatory procedures

 

Nepal Realistic Solution Responsibilities

• Facilitate process development efforts by ISMS team(s)
• Review developed policies/procedures against ISO 27001 standard and against organizational process improvement goals
• Review achievements of other planning goals, as appropriate
• Help make it happen!

 

Client Responsibilities

• Allocate resources, time and budget
• Develop and/or improve processes – make it happen!
• Apply developed ISMS processes
• Monitor and record progress of the pilot projects
• Have all results available for review and recommendations

 

PHASE IV: REVIEW – IMPLEMENTATION REVIEW AND INTERNAL AUDIT
Purpose The purpose of this step is to ensure that all the lessons learned data is available for starting an improvement process in the organization, for sustaining the process excellence. This activity involves creation of organizational process database and creates a memory for the organization to ensure that it does not repeat the mistakes.

Based on the lessons learnt, the step emphasizes on revising the organization approach to make changes more effectively, with reduced resistance and allowing process improvement to happen in a dynamic and rapid manner. In addition, this step involves revisiting of goals, sponsorship, and management commitment to enable better results.

For a sustained change culture in the organization, it is imperative that there are three cycles of improvement demonstrated for each process implemented in the organization for achieving a successful appraisal.

 

Objectives

• Create an organizational database for processes on lessons learnt
• Analyze processes & practices to make the process improvement effective
• Consider adding variations that will make the process improvement better
• Ensure that resources are available for continuous improvement
• Refine measurements and goals to objectively determine goal satisfaction

 

Activities

• Pilot the developed ISMS processes within the context of the scope
• of the IT service for which certification is being sought
• Tool customization/implementations
• Trainings and awareness (Including Internal Auditor Training)
• Carry out Internal Audits & review results with ISMS teams

 

Deliverables

• Institutionalized ISMS processes.
• Plan for improvements
• Internal assessments and audit reports
• Report on corrective actions

 

Nepal Realistic Solution Responsibilities

• Help select appropriate processes for piloting
• Review results of applying developed ISMS processes, in the context of ISMS requirements and the impact on the IT service, or service component, concerned
• Recommend changes
• Trainings (as required and agreed)
• Consult/assist/Mentor the Project team and Process owners.
• Provide support during external audit

 

Client Responsibilities

• Identify candidate processes for piloting
• Apply developed ISMS processes
• Monitor and record progress of the pilot projects
• Have all results available for review and recommendations

 

PHASE V: CERTIFICATION AUDIT
Purpose Certification of the ISMS by the certification body

Objectives

 

To ensure the defined management system is in compliance with ISO 27001:2013
Activities Conduct stage-1 audit (Document review) by certification body
Conduct stage -2 audit Certification audit by certification body

 

Deliverables

• Audit report
• Certificate from the certification body

 

Nepal Realistic Solution Responsibilities

• Coordinate with certification body
• Participate in stage 1 and stage 2 audit
• Close the Non-conformities, if any Recommend changes

 

Client Responsibilities

• Provide the resources to participate in the audit
• Provide the evidences during the audit

 

Timelines

Resource
Particulars : Mon1 Mon 2 Mon 3 Mon 4 Mon 5 Mon 6

Information Security Awareness Training Program to core Senior
1 Team Consultant
Detail Gap Assessment & Action Planning Senior
2 Consultant
Process Design and Development on Security Policies, Senior
3 Procedures, Templates, Checklists, Risk Assessment etc., Consultant
Process Implementation
– Conduct periodic Implementation Review Senior
– Internal Audit Training program for selected team Consultant
4 members
– Conduct Internal Audit by team Senior
– Close all open non-conformance – identified from Pre Consultant
5 Audit by Auditor

6 Stage 1 – Pre-Audit by Certification Body Lead Auditor
7 Stage 2 – Final Certification Audit by Certification Body Lead Auditor

Write A Comment
Categories
  • Business64
  • CE Marking4
  • Consultancy Services57
  • Consulting Firms49
  • Financial Service8
  • Human Capital15
  • Human Resource22
  • Internship In Nepal11
  • Inventory Management Service In Nepal3
  • ISO Certification Service70
  • ISO Consulting Service65
  • IT Security22
  • Management Consultancy41
  • Management Consulting43
  • Marketing Experts12
  • Marketing Strategy17
  • Presentation3
  • Social Media13
  • Strategy And Operation16
  • Support Start-Up Program8
  • Training21
  • Training Service In Nepal10
  • Uncategorized19
  • Vat & Tax Service In Nepal3
  • Writing6
Tags Cloud
100 Internship Program AI Marketing Airport Issues In Nepal Asset Management Best ISO Certification Provider BigData Boutique Management And Technology Brand Visibility Business Business Advisory In Nepal Business Consultancy Services Business Consultant Business Consultant In Nepal Business Consulting Business Consulting Company Business Consulting Expert Business Consulting Firm Business Consulting In Nepal Business Consulting Services Business Experts Business Growth Business Management Business Opportunity Business Plan Business Problems Business Setup Business Setup In Nepal Business Strategy Business Upgradation BusinessAnalytics BUSINESSCONSULTANT BusinessConsultantinNepal BusinessConsulting BusinessConsultingServices BusinessGrowth BusinessGrowth BusinessGrowth BusinessGrowth BusinessGrowth BusinessIntelligence BusinessManagement BusinessStrategy BusinessSuccess BusinessWebsite Busniess Consultant In Nepal Career Development Program Career Growth Career Progression CE Mark CE Marking CE Marking In Nepal Certification In Nepal Challenges In System Implementation CIA Triad In The ISO 27001 Company Setup In Nepal CompetentContract Construction Industry Consultancy Services Consulting Firms Contract Cost Effective Marketing Cost-efficient Marketing Strategy Courage Covid19 Creating Professionals Program Cyber Security Certification Cyber Security Certification Cyber Security With ISO 27001 CyberProtection Data Breach Pretection Data Protection Data Protection DataAnalytics DataDriven DataScience Develop Transferable Skills Digital Marketing Digital Marketing Digital Marketing Digital Marketing Digital Solutions Digital Training DigitalMarketing DigitalMarketingServices DigitalMarketingServices DigitalMarketingServices DigitalMarketingServices Education System Effective CV Writing Effective Leadership Effective Marketing EMAIL EMAILMARKETING Emergencies Employe Contract Employee Happiness Employee Training And Development Employee Welfare Employment Training Entrepreneurs Expert Business Consultants Financial Consulting Financial Structure First Aid First Aid Kit Flexibility At Work Food Safety And Management Certification Gain Experience Get ISO 9001 Certified In Australia Global ISO Consultant Good Manufacturing Practices Health And Safety HR Management Human Capital Human Capital Human Capital Consultancy Services Human Capital Consultants Human Capital Employment Center Human Capital Management Services Human Resource Human Resource Management Human Resource Services Human Resources Consultant Implementation Importance Of Public Relations In Business Ineligible Admissions Information Security Information Security Management System Information Security Management Systems Information Security Management Systems Information Technology Information Technology Cosulting InformationProtection InformationSecurity INFORMATIONTECHNOLOGY InternalAudit, ISO90012015, NepalRealisticSolution, QMS, Benefits, ISOTraining, Auditor International Internship International ISO Auditor In Australia International ISO Consultant In Australia International Management Consulting Company Internship Internship In Nepal Internship Opportunity Internship Program Inventory And Asset Inventory Management Investment Investors ISMS ISO 14000 ISO 14001 Certification ISO 14001 In Nepal ISO 14001 Services ISO 14001 Services In Austraila ISO 15189 ISO 15189 Services ISO 22000 Certification In Nepal ISO 22000 Certified ISO 22000 Services ISO 22000 Services In Austraila ISO 22000:2018 ISO 27001 Auditor Training ISO 27001 Austalia ISO 27001 Canada ISO 27001 Certificaiton Services ISO 27001 Certification ISO 27001 Certification In Australia ISO 27001 Certification In Canada ISO 27001 Certification In Nepal ISO 27001 Certification In UK ISO 27001 Certification Services ISO 27001 Certification Services ISO 27001 Clauses And Controls Iso 27001 Consultant ISO 27001 Consulting ISO 27001 Consulting Company ISO 27001 Consulting Service Iso 27001 Expert ISO 27001 Framework ISO 27001 Nepal ISO 27001 Services ISO 27001 Services Canada ISO 27001 Uk ISO 27001:2022 ISO 2701 Certification Company ISO 27701 Audit Process ISO 27701 Certification ISO 27701 Certification Service ISO 27701 Consulting ISO 45001 ISO 45001 Certificaiton Services ISo 45001 Guidelines ISO 45001 Services In Austraila ISO 55001 ISO 9001 Audit Australia Iso 9001 Auditor ISO 9001 Australia ISO 9001 Canada ISO 9001 Certification ISO 9001 Certification Australia ISO 9001 Certification Services ISO 9001 Certification Services In Nepal ISO 9001 Certifying Compnay In Australia ISO 9001 Compliance Training ISO 9001 Consulting ISO 9001 Internal Auditor Training ISO 9001 Nepal ISO 9001 QMS Certification ISO 9001 Services ISO 9001 Services In Austraila ISO 9001 Training Nepal ISO 9001 UK ISO 9001:2015 ISO 9001:Quality Management System ISO Audits ISO Certificaion Company ISO Certificaiton Company In Nepal ISO Certificaiton In Australia ISO Certificaiton In Canada ISO Certificaiton In UK ISO Certification ISO Certification Company ISO Certification Company Canada ISO Certification In Nepal ISO Certification In Nepal ISO Certification Process ISO Certification Services ISO Certification Services In Australia ISO Consultancy Firm ISO Consultancy Services ISO Consultancy Services ISO Consultant ISO Consultant In Canada ISO Consultant In Nepal ISO Consulting And Certification Company In Nepal ISO Consulting Cmpany In Australia ISO Consulting Company ISO Consulting Company In Australia ISO Consulting Firm ISO Consulting In Australia ISO Consulting Service ISO Consulting Services ISO Consulting Services In Australia ISO Expert ISO Expert Consultants ISO Services ISO Standard ISO Standard 9001 ISO Standard Certificaiton ISO Standard For Medical Labs ISO Standards ISO Training For Business ISO_Consultancy_In_Nepal ISO14001 ISO14001 ISO27001 ISO270012022 ISO9001 ISOCERTIFICATION ISOCERTIFIED ISOCONSULTANCYSERVICES ISOSTANDARDCERTIFICATIONINNEPAL ISOSTANDARDS IT IT Consultant It Consulting IT Consulting Offices In Nepal IT Development IT Management IT Secutiy Services IT Strategy ITConsultingNepal ITservices ITSTRATEGY Knowing Yourself Leadership Leading ISO Consulting Company Learn Management Management And Consultancy Firm Management And Technology Consulting Management Consultant Management Consultant In Nepal Management Consultant In Nepal Management Consulting Management Consulting Firm Management System ManagementConsulting MANAGEMENTCONSULTINGFIRM Manufacturing Companies Manufacturing Practices Market Marketing Marketing Analysis Marketing Communication Strategy Marketing Experts Marketing Research Marketing Strategy Media Communication Strategy Negligence In Work Environment Nepal Realistic Solution Nepal Realistic Solution Nepal Realistic Solution Nepal Realistic Solution Nepal Realistic Solution, Training Services Nepal’s Tax Structure NEPALREALISTICSOLUTION Network Security Services NRS Karmakar NRS Nursing Occupational Health And Safety Online Platform Online Presence OnlineBrandBuilding OnlineMarketing OnlineMarketing OnlineMarketing OnlineMarketing OnlineMarketing Organisational Growth Overcoming Writer’s Overcoming Writer’s Block Pandemic Personal Information Management System Planning Presentations Privacy Protection Privacy Protection Process Approach PROFESSIONALEMAIL Public Relation And Business Public Relations Public Relations Professionals QMS Training In Nepal Quality Management Quality Management System Training Quality Management System, Training Services Quarantine Recertify_ISO Recruitment Agency Research And Development Responsibilities Of PR Practitioner RiskAssessment RiskManagement Safety First Safety Standards Security SEDEX Audit SEDEX Certification SEDEX Certification In Nepal Self Development SEO Class Skills SMETA SMETA Certification In Nepal Social Audit Social Media Social Media Addiction Social Media Platforms Social Media Strategies Social Media Strategy Social Networking Sites Social Responsibility Start-Ups In Nepal Strategy And Operation Successful Interview Successfull Presentation Supplier Audit Support Start- Up Support Start-Up Program Taxation System In Nepal Technical Consulting TechnicalConsulting TECHNICALCONSULTING Techniques To Read Quickly Technological Innovations The Environmental Impact Top ISO Certification Provider Top ISO Consulting Firm Training Training Training Services TrainingandEducationalServices TrainingcompaniesNepal Travel And Tourism Travel Nepal Upgrade_ISO_9001_2008_to_9001_2015 WebConsulting Website Development Website Optimization WebsiteDevelopment WebSolutions Work From Home Work Place Safety Work Process Writer’s Block
Archive
  • April 20251
  • March 20251
  • February 20253
  • January 20253
  • December 20245
  • November 20243
  • October 20245
  • September 20244
  • July 20243
  • June 20244
  • May 20244
  • April 20244
  • March 20244
  • February 20245
  • January 20244
  • December 20233
  • November 20235
  • August 20231
  • May 20231
  • April 20232
  • February 20234
  • January 20235
  • December 20223
  • November 20221
  • September 20221
  • July 20221
  • June 20221
  • May 20222
  • April 20222
  • March 20222
  • February 20224
  • January 20223
  • December 20215
  • November 20214
  • October 20214
  • September 20215
  • August 20211
  • July 20212
  • June 20212
  • May 20212
  • April 20213
  • January 20211
  • December 20203
  • November 20202
  • October 20201
  • September 20203
  • August 20203
  • June 20203
  • May 20202
  • April 20202
  • March 20204
  • February 20203
  • January 20205
  • December 20192
  • November 20192
  • October 20193
  • September 20192
  • August 20193
  • July 20191
  • June 20192
  • May 20192
  • April 20194
  • March 20193
  • February 20191
  • December 20181
  • October 20181
  • September 20181
  • August 20181
  • July 20184
  • June 20181
  • April 20182
  • February 20181
  • December 20171
  • November 20171
  • October 20171
  • September 20177
  • August 20175
  • July 20172
Pofo
ISO 9001 | ISO / IEC 27001 Certified Company

We are a multinational business consulting firm, based in the UK, Canada, Australia, and Nepal, offering ISO certification, cutting-edge technology solutions, strategic business advisory, human resources management, financial consulting, and operational optimization solutions to businesses globally through a team of experts.

Important Links
  • Disclaimer
  • Privacy Policy
  • Our Team
  • Alliances
  • Current Activities
  • FAQs
  • Sitemap
  • Career
  • Internship
  • Education & Training
Contact Info

Addr: Nepal Realistic Solution
Minbhawan, New Baneshwor, Kathmandu, Nepal

Addr: Nepal Realistic Solution
251 Consumers Rd, 1200, Toronto, Ontario, Canada,M2J4R3

Email: info@nrsnepal.com
Copyright © 2015, All rights reserved Nepal Realistic Solution