Search alphaZ documents
Products meeting the search criteria
Policy-procedure on anti-malware which details the arrangements in place to protect all information assets from malware and the controls in place within the organisation.Procedure includes;- Mana..
Policy-procedure detailing the arrangements in place to control the use of software used on equipment and the installation of software on IT equipment and handheld devices.Procedure covers;- Control o..
Policy-procedure detailing the arrangements in place to manage and control access to information throughout the organisation to prevent unauthorised access.Procedure covers;- Management of Risks Assoc..
Policy-procedure detailing the arrangements in place to control the use of internet and electronic messaging within the organisation.Procedure includes: -Management of Risks Associated with Electronic..
Policy-procedure on information transfer detailing the arrangements in place to control and protect information during any type of transfer as part of the business activities being carried out.Procedu..
Policy-procedure detailing the arrangements in place to detect and prevent any technical vulnerability and the control in place within the organisation.Procedure covers;Management of Risks Associated ..
Policy-procedure on secure development that outlines the controls to ensure Information Security is incorporated into project management methodology, regardless of type or owner of project.Procedure c..
Policy-procedure detailing the arrangements in place to outline the process for cloud computing used within the company and the controls in place.Procedure covers;Management of Risks Associated with C..
Policy-procedure detailing the arrangements in place for the management and protection of user secret authentication identification which is controlled within the organisation.Procedure covers;Managem..
Policy-procedure detailing the arrangements in place to manage and control information security related to any activities outsourced to third parties.Procedure includes;Management of Risks Associated ..
Policy-procedure detailing the arrangements in place to manage the classification of information used within the organisation and how it is protected.Procedure includes;Management of Risks associated ..
This information security policy-procedure includes a large number of topic-specific information security policies including the following;Information Communication Technology (ICT) Equipment PolicyUs..
Using this example is a real head-start when preparing an information security risk assessment for a small office, and it gives you solid input for your information security risk register.Effective fo..
With a virtual company there is no building to worry about, so the risks sit with people, their laptops and the cloud apps they log into. This example gathers them in one place, which makes putting yo..
When I review a larger organisation's risk assessment I want to see the main information security risks set out clearly with the controls that manage them. This example does exactly that and gives you..
Phishing and social engineering are as much about people as technology. This example is a great starting point for assessing those risks and provides useful input for your information security risk re..
The important thing with ransomware is what happens once prevention fails. This example covers detection and recovery alongside the defences, so it is a useful head-start for your assessment and shows..
This is an example risk assessment that lists the key cloud computing risks for you. It makes preparing your own much easier than starting from a blank page.Effective form templatesThis example risk a..
This is an example risk assessment covering the main cyber attack risks and the controls that manage them. It makes preparing your own much easier than starting from a blank page.Effective form templa..
This is an example risk assessment covering the main risks from mobile devices and remote access. It is a real time-saver compared with preparing your own from a blank page.Effective form templatesThi..
This is an example risk assessment covering the main data protection and privacy risks and the controls that manage them. It makes preparing your own much easier than starting from a blank page.Effect..
General guidance the arrangements in place to manage own and externally supplied documents, files and records.Topics covered;Management of Files and FoldersDocument register & issue controlFile Na..
General guidance on what an IMS (Integrated Management System) is and what this means to all workers.Topics covered;Purpose of the management systemCommon Management System StandardsSetting up an IMSH..
General guidance on Internal Audits detailing what an Internal Audits are how they are carried out and how they can benefit the businessTopics covered;Purpose of internal audits / auditingType of Audi..
General guidance on completion of management review and setting objectives.Topics covered;Management ReviewCompany ObjectivesObjectives for quality, environmental, health & safety and information ..
General guidance on ISO management system standards and the ISO certification process.Topics covered;ISO standards overviewISO CertificationThe External Certification AuditPreparing for the auditISO c..
This general guidance document outlines the considerations and measures companies must address for data protection. An overview and definition is provided in addition to:Compliance Personal..