<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-6214940178721092651</atom:id><lastBuildDate>Sat, 05 Oct 2024 02:03:50 +0000</lastBuildDate><category>konsultan ISO 27001:2013</category><category>training ISO 27001:2013</category><category>pelatihan ISO 27001:2013</category><category>Audit TI</category><category>BS 7799</category><category>ISMS</category><category>ISO 17799</category><category>IT Audit</category><category>IT security</category><category>consultant</category><category>internet security</category><category>iso 27000</category><category>iso 27001</category><category>keamanan TI</category><category>keamanan informasi</category><category>konsultan</category><category>training iso 27001</category><category>ISO 27001:2013 vs ISO 27001:2005</category><category>SMKI ISO 27001</category><category>SOA</category><category>business security</category><category>download ISO 27001:2013</category><category>information security controls</category><category>iso 27001:2005</category><category>kendali keamanan informasi</category><category>kontrol keamanan informasi</category><category>manfaat ISO 27001</category><category>perbedaan ISO 27001:2013</category><category>perubahan ISO 27001:2005</category><category>revisi ISO 27001:2005</category><category>risk</category><category>security control</category><category>security requirement</category><category>seminar ISO 27001:2013</category><category>sertifikasi TI</category><category>sistem manajemen keamanan informasi</category><category>struktur ISO 27001:2013</category><category>susunan ISO 27001:2013</category><title>KONSULTAN SERTIFIKASI SMKI ISO 27001 TRAINING SEMINAR PELATIHAN MANAJEMEN KEAMANAN INFORMASI</title><description>Info konsultan sertifikasi smki ISO 27001:2013 training seminar pelatihan sistim manajemen keamanan informasi download manual prosedur audit TI internal auditor kendali kontrol asesmen risiko statement of applicability soa murah cepat profesional</description><link>http://iso-27001-info.blogspot.com/</link><managingEditor>noreply@blogger.com (Unknown)</managingEditor><generator>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6214940178721092651.post-5287976357604721151</guid><pubDate>Mon, 21 Oct 2013 14:44:00 +0000</pubDate><atom:updated>2013-10-21T21:44:24.469+07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information security controls</category><category domain="http://www.blogger.com/atom/ns#">kendali keamanan informasi</category><category domain="http://www.blogger.com/atom/ns#">kontrol keamanan informasi</category><category domain="http://www.blogger.com/atom/ns#">sistem manajemen keamanan informasi</category><category domain="http://www.blogger.com/atom/ns#">SMKI ISO 27001</category><title>Kendali Keamanan Baru (new information security controls) Pada ISO 27001:2013</title><description>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5PBs9mOtQUbMsO7xrB3tLT4CUWqglZXsQALcWVyp5JDSgEFYBOVWJ7YF-A5uxpmP5b9q8JIL6DPah8J95nZqQRep6tetKq3fXqjfaD05EE1h2abbPsnCVqrmDrj5eE6p0D7UmYYKv1sY/s1600/woman-man-computer.jpg&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;184&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5PBs9mOtQUbMsO7xrB3tLT4CUWqglZXsQALcWVyp5JDSgEFYBOVWJ7YF-A5uxpmP5b9q8JIL6DPah8J95nZqQRep6tetKq3fXqjfaD05EE1h2abbPsnCVqrmDrj5eE6p0D7UmYYKv1sY/s200/woman-man-computer.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Beberapa kendali keamanan informasi baru (new information security controls) yang ditambahkan pada &lt;strong&gt;ISO 27001:2013&lt;/strong&gt; ini di antaranya:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;A.6.1.5 Information security in project management&lt;/li&gt;
&lt;li&gt;A.12.6.2 Restrictions on software installation&lt;/li&gt;
&lt;li&gt;A.14.2.1 Secure development policy&lt;/li&gt;
&lt;li&gt;A.14.2.5 Secure system engineering principles&lt;/li&gt;
&lt;li&gt;A.14.2.6 Secure development environment&lt;/li&gt;
&lt;li&gt;A.14.2.8 System security testing&lt;/li&gt;
&lt;li&gt;A.15.1.1 Information security policy for supplier relationships&lt;/li&gt;
&lt;li&gt;A.15.1.3 Information and communication technology supply chain&lt;/li&gt;
&lt;li&gt;A.16.1.4 Assessment of and decision on information security events&lt;/li&gt;
&lt;li&gt;A.16.1.5 Response to information security incidents&lt;/li&gt;
&lt;li&gt;A.17.2.1 Availability of information processing facilities&lt;/li&gt;
&lt;/ul&gt;
</description><link>http://iso-27001-info.blogspot.com/2013/10/kendali-keamanan-baru-new-information.html</link><author>noreply@blogger.com (Unknown)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5PBs9mOtQUbMsO7xrB3tLT4CUWqglZXsQALcWVyp5JDSgEFYBOVWJ7YF-A5uxpmP5b9q8JIL6DPah8J95nZqQRep6tetKq3fXqjfaD05EE1h2abbPsnCVqrmDrj5eE6p0D7UmYYKv1sY/s72-c/woman-man-computer.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6214940178721092651.post-3354044899205873651</guid><pubDate>Mon, 21 Oct 2013 14:39:00 +0000</pubDate><atom:updated>2013-10-21T21:39:54.051+07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">download ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">konsultan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">pelatihan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">struktur ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">susunan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">training ISO 27001:2013</category><title>Struktur Standar Internasional ISO 27001:2013</title><description>&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;strong&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhL3XbiKfmfK4rokYg-RbvzHQzatuLWkxZ7ZDAcvKiRtV4pENKzzFXUzSLQBRQlhMUnszcAWAdu5kEMP-mNMTB7Fh7_zIDtd8cokkHwvZH4LP5cGGaJ5iGcRyPVHJ2TO3JWJIMu23YpDDE/s1600/security300x350.jpg&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhL3XbiKfmfK4rokYg-RbvzHQzatuLWkxZ7ZDAcvKiRtV4pENKzzFXUzSLQBRQlhMUnszcAWAdu5kEMP-mNMTB7Fh7_zIDtd8cokkHwvZH4LP5cGGaJ5iGcRyPVHJ2TO3JWJIMu23YpDDE/s200/security300x350.jpg&quot; width=&quot;171&quot; /&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;strong&gt;Struktur standar ISO 27001:2013&lt;/strong&gt;&lt;br /&gt;
&lt;dl&gt;&lt;dd&gt;1. Scope of the standard&lt;/dd&gt;&lt;dd&gt;2. How the document is referenced&lt;/dd&gt;&lt;dd&gt;3. Reuse of the terms and definitions in ISO/IEC&amp;nbsp;27000&lt;/dd&gt;&lt;dd&gt;4. Organizational context and stakeholders&lt;/dd&gt;&lt;dd&gt;5. Information security leadership and high-level support for policy&lt;/dd&gt;&lt;dd&gt;6. Planning an information security management system; risk assessment; risk treatment&lt;/dd&gt;&lt;dd&gt;7. Supporting an information security management system&lt;/dd&gt;&lt;dd&gt;8. Making an information security management system operational&lt;/dd&gt;&lt;dd&gt;9. Reviewing the system’s performance&lt;/dd&gt;&lt;dd&gt;10. Corrective action&lt;/dd&gt;&lt;dd&gt;Annex A: List of controls and their objectives.&lt;/dd&gt;&lt;/dl&gt;
</description><link>http://iso-27001-info.blogspot.com/2013/10/struktur-standar-internasional-iso.html</link><author>noreply@blogger.com (Unknown)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhL3XbiKfmfK4rokYg-RbvzHQzatuLWkxZ7ZDAcvKiRtV4pENKzzFXUzSLQBRQlhMUnszcAWAdu5kEMP-mNMTB7Fh7_zIDtd8cokkHwvZH4LP5cGGaJ5iGcRyPVHJ2TO3JWJIMu23YpDDE/s72-c/security300x350.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6214940178721092651.post-3494310511412701903</guid><pubDate>Mon, 21 Oct 2013 14:36:00 +0000</pubDate><atom:updated>2013-10-21T21:36:24.994+07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">ISO 27001:2013 vs ISO 27001:2005</category><category domain="http://www.blogger.com/atom/ns#">konsultan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">pelatihan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">seminar ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">training ISO 27001:2013</category><title>Perbedaan ISO 27001:2013 vs ISO 27001:2005</title><description>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLc8lfnF6y4UHCRnv74FEfoH2KqaV7sS9PjVHVn5JT0ePfd-H2PSQw9BngVyMH0AAgfINkS9EckVhaT8zA7sx0j39Vdwgz4DovXbHUJlGLP7me3j9FSeKocOudJU4nVqtfDIVAOZKwszo/s1600/iso_27001_information_security.jpg&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLc8lfnF6y4UHCRnv74FEfoH2KqaV7sS9PjVHVn5JT0ePfd-H2PSQw9BngVyMH0AAgfINkS9EckVhaT8zA7sx0j39Vdwgz4DovXbHUJlGLP7me3j9FSeKocOudJU4nVqtfDIVAOZKwszo/s1600/iso_27001_information_security.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Standar internasional &lt;b&gt;ISO 27001:2013 &lt;/b&gt;menampilkan 114 kendali 
(control) dalam 14 kelompok domain, dibandingkan standar sebelumnya yang
 terdiri dari 133 kendali dalam 11 kelompok domain. Perubahan pada 
persyaratan revisi 2013 ini merefleksikan perubahan teknologi yang 
banyak berdampak pada kelangsungan bisnis saat ini, misalnya 
perkembangan teknologi komputasi awan (cloud computing).&lt;br /&gt;
&lt;br /&gt;
Mengenai perbedaan antara ISO 27001:2013 dan ISO 27001:2005 di antaranya adalah susunan kendali keamanan pada &lt;strong&gt;Annex A&lt;/strong&gt; telah berubah menjadi:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;A.5: Information security policies&lt;/li&gt;
&lt;li&gt;A.6: Information security organisation&lt;/li&gt;
&lt;li&gt;A.7: Human resources security&lt;/li&gt;
&lt;li&gt;A.8: Asset management&lt;/li&gt;
&lt;li&gt;A.9: Access controls and managing user access&lt;/li&gt;
&lt;li&gt;A.10: Cryptographic technology&lt;/li&gt;
&lt;li&gt;A.11: Physical security&lt;/li&gt;
&lt;li&gt;A.12: Operational security&lt;/li&gt;
&lt;li&gt;A.13: Secure communications and data transfer&lt;/li&gt;
&lt;li&gt;A.14: Secure acquisition, development, and support of information systems&lt;/li&gt;
&lt;li&gt;A.15: Security for suppliers and third parties&lt;/li&gt;
&lt;li&gt;A.16: Incident management&lt;/li&gt;
&lt;li&gt;A.17: Business continuity/disaster recovery&lt;/li&gt;
&lt;li&gt;A.18: Compliance&lt;/li&gt;
&lt;/ul&gt;
</description><link>http://iso-27001-info.blogspot.com/2013/10/perbedaan-iso-270012013-vs-iso-270012005.html</link><author>noreply@blogger.com (Unknown)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLc8lfnF6y4UHCRnv74FEfoH2KqaV7sS9PjVHVn5JT0ePfd-H2PSQw9BngVyMH0AAgfINkS9EckVhaT8zA7sx0j39Vdwgz4DovXbHUJlGLP7me3j9FSeKocOudJU4nVqtfDIVAOZKwszo/s72-c/iso_27001_information_security.jpg" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6214940178721092651.post-5901581409175802437</guid><pubDate>Mon, 21 Oct 2013 14:31:00 +0000</pubDate><atom:updated>2013-10-21T21:31:47.057+07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">konsultan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">perbedaan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">perubahan ISO 27001:2005</category><category domain="http://www.blogger.com/atom/ns#">revisi ISO 27001:2005</category><category domain="http://www.blogger.com/atom/ns#">training ISO 27001:2013</category><title>Revisi ISO 27001:2005 menjadi ISO 27001:2013</title><description>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmrWAJdt46z4mTmt1fn8sFBZbjDpT6L8uMJjup3DdnCijMICCXx8uc4nANeU1ODp0I3LmNJ9TyxdCq7A-TwlHx9pihiCD3jhwCwxrGmtf_0rSjA8Ibw6LnXXF9Blv_hLY-B8LcWyVh4t4/s1600/ISO+27001_000003923113Medium.jpg&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;133&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmrWAJdt46z4mTmt1fn8sFBZbjDpT6L8uMJjup3DdnCijMICCXx8uc4nANeU1ODp0I3LmNJ9TyxdCq7A-TwlHx9pihiCD3jhwCwxrGmtf_0rSjA8Ibw6LnXXF9Blv_hLY-B8LcWyVh4t4/s200/ISO+27001_000003923113Medium.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Standar keamanan informasi ISO 27001 versi 2013 telah dipublikasikan 
pada tanggal 25 September 2013 oleh International Organization for 
Standardization (ISO). Standar ini disingkat dengan sebutan &lt;strong&gt;ISO 27001:2013&lt;/strong&gt;,
 berisi spesifikasi bagi sistem manajemen keamanan informasi 
(information security management system). Dengan demikian standar ini 
membatalkan dan menggantikan standar versi sebelumnya yaitu ISO 
27001:2005. Secara umum standar ISO 27001:2013 dikembangkan agar lebih 
selaras dengan standar sistem manajemen lainnya seperti ISO 9001 dan ISO
 20000.</description><link>http://iso-27001-info.blogspot.com/2013/10/revisi-iso-270012005-menjadi-iso.html</link><author>noreply@blogger.com (Unknown)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmrWAJdt46z4mTmt1fn8sFBZbjDpT6L8uMJjup3DdnCijMICCXx8uc4nANeU1ODp0I3LmNJ9TyxdCq7A-TwlHx9pihiCD3jhwCwxrGmtf_0rSjA8Ibw6LnXXF9Blv_hLY-B8LcWyVh4t4/s72-c/ISO+27001_000003923113Medium.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6214940178721092651.post-6997406660786269680</guid><pubDate>Tue, 17 Mar 2009 19:32:00 +0000</pubDate><atom:updated>2013-10-21T21:46:48.736+07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">business security</category><category domain="http://www.blogger.com/atom/ns#">iso 27001:2005</category><category domain="http://www.blogger.com/atom/ns#">konsultan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">manfaat ISO 27001</category><category domain="http://www.blogger.com/atom/ns#">pelatihan ISO 27001:2013</category><category domain="http://www.blogger.com/atom/ns#">security control</category><category domain="http://www.blogger.com/atom/ns#">security requirement</category><category domain="http://www.blogger.com/atom/ns#">training ISO 27001:2013</category><title>Manfaat ISO 27001</title><description>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY2DyPJn4NO2rs2R5Xk9be8Jzbi_x74ihg7gFrXjsnjF2M9vYzlL6l0ys9J6fEk-HEQCm7ULtCRTBNihrY4-Xh8CcLY64BT7BQJjQ4fR6S1Kjoffz6vK2b-kFRuGXGkCK5Hz20EKl-feI/s1600/shapeimage_3.jpg&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;111&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY2DyPJn4NO2rs2R5Xk9be8Jzbi_x74ihg7gFrXjsnjF2M9vYzlL6l0ys9J6fEk-HEQCm7ULtCRTBNihrY4-Xh8CcLY64BT7BQJjQ4fR6S1Kjoffz6vK2b-kFRuGXGkCK5Hz20EKl-feI/s200/shapeimage_3.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
ISO/IEC 27001 is intended to be suitable for several different types of use, including the following:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;use within organizations to formulate security requirements and objectives; &lt;/li&gt;
&lt;li&gt;use within organizations as a way to ensure that security risks are cost effectively managed; &lt;/li&gt;
&lt;li&gt;use within organizations to ensure compliance with laws and regulations; &lt;/li&gt;
&lt;li&gt;use within an organization as a process framework for the implementation and management of controls to ensure that the specific security objectives of an organization are met; &lt;/li&gt;
&lt;li&gt;definition of new information security management processes; &lt;/li&gt;
&lt;li&gt;identification and clarification of existing information security management processes; &lt;/li&gt;
&lt;li&gt;use by the management of organizations to determine the status of information security management activities; &lt;/li&gt;
&lt;li&gt;use by the internal and external auditors of organizations to determine the degree of compliance with the policies, directives and standards adopted by an organization; &lt;/li&gt;
&lt;li&gt;use by organizations to provide relevant information about information security policies, directives, standards and procedures to trading partners and other organizations with whom they interact for operational or commercial reasons;&lt;br /&gt;implementation of business-enabling information security; &lt;/li&gt;
&lt;li&gt;use by organizations to provide relevant information about information security to customers.&lt;/li&gt;
&lt;/ul&gt;
</description><link>http://iso-27001-info.blogspot.com/2009/03/manfaat-iso-27001.html</link><author>noreply@blogger.com (Unknown)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY2DyPJn4NO2rs2R5Xk9be8Jzbi_x74ihg7gFrXjsnjF2M9vYzlL6l0ys9J6fEk-HEQCm7ULtCRTBNihrY4-Xh8CcLY64BT7BQJjQ4fR6S1Kjoffz6vK2b-kFRuGXGkCK5Hz20EKl-feI/s72-c/shapeimage_3.jpg" height="72" width="72"/><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6214940178721092651.post-485674885955189297</guid><pubDate>Tue, 17 Mar 2009 19:23:00 +0000</pubDate><atom:updated>2013-10-21T21:48:14.311+07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Audit TI</category><category domain="http://www.blogger.com/atom/ns#">BS 7799</category><category domain="http://www.blogger.com/atom/ns#">consultant</category><category domain="http://www.blogger.com/atom/ns#">internet security</category><category domain="http://www.blogger.com/atom/ns#">ISMS</category><category domain="http://www.blogger.com/atom/ns#">ISO 17799</category><category domain="http://www.blogger.com/atom/ns#">iso 27000</category><category domain="http://www.blogger.com/atom/ns#">iso 27001</category><category domain="http://www.blogger.com/atom/ns#">IT Audit</category><category domain="http://www.blogger.com/atom/ns#">IT security</category><category domain="http://www.blogger.com/atom/ns#">keamanan informasi</category><category domain="http://www.blogger.com/atom/ns#">keamanan TI</category><category domain="http://www.blogger.com/atom/ns#">konsultan</category><category domain="http://www.blogger.com/atom/ns#">risk</category><category domain="http://www.blogger.com/atom/ns#">SOA</category><category domain="http://www.blogger.com/atom/ns#">training iso 27001</category><title>Audit Sertifikasi ISO 27001</title><description>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxt08ASZ7mprNFUQOHOblvqXLsSrBAjyU3NtpP6YL-NZS_6KnGrFtgmDc5ivtL5h-lTL4thunaSjFjG9LnmDMMEtzjy_FqHlxIZppdHzfNYLfSPIJEawCPjkVBnb255tErcd6sEFp_sEc/s1600/icon_networks.jpg&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxt08ASZ7mprNFUQOHOblvqXLsSrBAjyU3NtpP6YL-NZS_6KnGrFtgmDc5ivtL5h-lTL4thunaSjFjG9LnmDMMEtzjy_FqHlxIZppdHzfNYLfSPIJEawCPjkVBnb255tErcd6sEFp_sEc/s200/icon_networks.jpg&quot; width=&quot;150&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Organizations may be certified as compliant with ISO/IEC 27001 by a number of &lt;a class=&quot;mw-redirect&quot; href=&quot;http://en.wikipedia.org/wiki/Accredited_Registrar&quot; title=&quot;Accredited Registrar&quot;&gt;Accredited Registrars&lt;/a&gt; worldwide. &lt;a href=&quot;http://en.wikipedia.org/wiki/Certification&quot; title=&quot;Certification&quot;&gt;Certification&lt;/a&gt; against any of the recognized national variants of ISO/IEC 27001 (e.g. JIS Q 27001, the Japanese version) by an accredited certification body is functionally equivalent to certification against ISO/IEC 27001 itself. Certification &lt;a href=&quot;http://en.wikipedia.org/wiki/Audit&quot; title=&quot;Audit&quot;&gt;audits&lt;/a&gt; are usually conducted by ISO/IEC 27001 Lead Auditors.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In some countries, the bodies which verify conformity of management systems to specified standards are called &quot;certification bodies&quot;, in others they are known as &quot;registration bodies&quot;, &quot;assessment and registration bodies&quot;, &quot;certification/ registration bodies&quot;, and sometimes &quot;registrars&quot;.&lt;br /&gt;
The ISO/IEC 27001 certification&lt;a href=&quot;http://en.wikipedia.org/wiki/ISO_27001#cite_note-0&quot; title=&quot;&quot;&gt;[1]&lt;/a&gt;, like other ISO management system certifications, usually involves a three-stage audit process:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Stage 1 is a &quot;table top&quot; review of the existence and completeness of key documentation such as the organization&#39;s security policy, Statement of Applicability (SoA) and Risk Treatment Plan (RTP).&lt;br /&gt;
Stage 2 is a detailed, in-depth audit involving testing the existence and effectiveness of the information security controls stated in the SoA and RTP, as well as their supporting documentation.&lt;br /&gt;
Stage 3 is a follow-up reassessment audit to confirm that a previously-certified organization remains in compliance with the standard. Certification maintenance involves periodic reviews and re-assessments to confirm that the &lt;a class=&quot;mw-redirect&quot; href=&quot;http://en.wikipedia.org/wiki/ISMS&quot; title=&quot;ISMS&quot;&gt;ISMS&lt;/a&gt; continues to operate as specified and intended.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;span style=&quot;font-size: 85%;&quot;&gt;(this article is taken from wikipedia)&lt;/span&gt;&lt;/i&gt;</description><link>http://iso-27001-info.blogspot.com/2009/03/audit-sertifikasi-iso-27001.html</link><author>noreply@blogger.com (Unknown)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxt08ASZ7mprNFUQOHOblvqXLsSrBAjyU3NtpP6YL-NZS_6KnGrFtgmDc5ivtL5h-lTL4thunaSjFjG9LnmDMMEtzjy_FqHlxIZppdHzfNYLfSPIJEawCPjkVBnb255tErcd6sEFp_sEc/s72-c/icon_networks.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6214940178721092651.post-8635189664563304385</guid><pubDate>Tue, 17 Mar 2009 18:43:00 +0000</pubDate><atom:updated>2009-03-18T02:16:57.174+07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Audit TI</category><category domain="http://www.blogger.com/atom/ns#">BS 7799</category><category domain="http://www.blogger.com/atom/ns#">consultant</category><category domain="http://www.blogger.com/atom/ns#">internet security</category><category domain="http://www.blogger.com/atom/ns#">ISMS</category><category domain="http://www.blogger.com/atom/ns#">ISO 17799</category><category domain="http://www.blogger.com/atom/ns#">iso 27000</category><category domain="http://www.blogger.com/atom/ns#">iso 27001</category><category domain="http://www.blogger.com/atom/ns#">IT Audit</category><category domain="http://www.blogger.com/atom/ns#">IT security</category><category domain="http://www.blogger.com/atom/ns#">keamanan informasi</category><category domain="http://www.blogger.com/atom/ns#">keamanan TI</category><category domain="http://www.blogger.com/atom/ns#">konsultan</category><category domain="http://www.blogger.com/atom/ns#">sertifikasi TI</category><category domain="http://www.blogger.com/atom/ns#">training iso 27001</category><title>ISO IEC 27001</title><description>&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipplK_jf_0wFS5_Ds94NuC8Zfl32apSyDq4z8VpwriRKFNGojRZOEun2utgntriJ4x7_vJZvury5tXBbLX917G1YiIvTLlIGbbniz9S8xXD9BtXnmUAHse9_L6ULSohcgYiR9xIwcn7FM/s1600-h/konsultan_iso_27000_27001_manajemen_keamanan_informasi_isms_it_security_consultant_iso_17799_training_audit_consultant_keamanan_ti.JPG&quot;&gt;&lt;img id=&quot;BLOGGER_PHOTO_ID_5314237790219357266&quot; style=&quot;FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 200px; CURSOR: hand; HEIGHT: 150px&quot; alt=&quot;&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipplK_jf_0wFS5_Ds94NuC8Zfl32apSyDq4z8VpwriRKFNGojRZOEun2utgntriJ4x7_vJZvury5tXBbLX917G1YiIvTLlIGbbniz9S8xXD9BtXnmUAHse9_L6ULSohcgYiR9xIwcn7FM/s200/konsultan_iso_27000_27001_manajemen_keamanan_informasi_isms_it_security_consultant_iso_17799_training_audit_consultant_keamanan_ti.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;ISO IEC 27001 International Standard covers all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations). This International Standard specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented ISMS within the context of the organization’s overall business risks. It specifies requirements for the implementation of security controls customized to the needs of individual organizations or parts thereof. The ISMS is designed to ensure the selection of adequate and proportionate security controls that protect information assets and give confidence to interested parties.&lt;/div&gt;</description><link>http://iso-27001-info.blogspot.com/2009/03/iso-iec-27001.html</link><author>noreply@blogger.com (Unknown)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipplK_jf_0wFS5_Ds94NuC8Zfl32apSyDq4z8VpwriRKFNGojRZOEun2utgntriJ4x7_vJZvury5tXBbLX917G1YiIvTLlIGbbniz9S8xXD9BtXnmUAHse9_L6ULSohcgYiR9xIwcn7FM/s72-c/konsultan_iso_27000_27001_manajemen_keamanan_informasi_isms_it_security_consultant_iso_17799_training_audit_consultant_keamanan_ti.JPG" height="72" width="72"/><thr:total>0</thr:total></item></channel></rss>