▲ Back to Top
Information Asset Management
In this management process, it is required to identify, assess, and classify the most important information assets of the business. An information asset in the context of an ISMS and based on the ISO/IEC 27001 standard is: “something to which an organization directly assigns a value and therefore the organization must protect.”.
STAGES
1. PLAN
2. DO
3. VERIFY
4. ACT
-
- Define what an information asset is for the organization.
-
- Establish a method for the identification and valuation of information assets.
-
- Define a classification scheme.
-
- Establish the treatment and management for information assets at each established classification level.
-
- Gathering information on the information assets used in the organization's processes.
-
- Identify and value information assets.
-
- Classify information assets.
-
- Incorporate the defined treatment and handling for each classification level into the day-to-day activities within the organization's processes.
-
- Review the assessments made on information assets if changes occur in the business or technology.
-
- Conduct a quality review of the information recorded in the inventory.
-
- Conduct compliance audits of treatment and handling in accordance with the stipulated classification levels.
-
- Update the asset inventory information.
-
- Advance the recommendations resulting from the audits performed.
OTRAS ETAPAS DEL MODELO
SGSI
SGSI
SGSI
SGSI
