Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 3

CASE STUDY – Cyber Strategy & Governance

Case : You are doing ISO 27001 audit of XYZ organization & you observed that one of the employee has shared company sensitive information on his personal Gmail
account
09/04/2024 CONFIDENTIAL 1
ISO 27001 is the international standard that describes best practice for an ISMS (information security
management system).The Standard takes a risk-based approach to information security.

Annexures Controls

Annex A.13: Communication • Network Security Management


Security • Information Transfer

Annex A.13: Human Resource • Prior to Employment


Security • During Employment

Annex A.13: Organization of • Internal Organization


Information Security • Teleworking

• Responsibility of Assets
Annex A.13: Asset
• Information Classification
Management
09/04/2024 CONFIDENTIAL 2
09/04/2024 CONFIDENTIAL 3

You might also like