Procedure for Specialist Information Security Advice

Details

DateVersionStatusInformation ClassificationDocument Template IDDocument No
19-02-20201.0ApprovedInternalAMS DOC

Revision History

DateVersionDescriptionAuthorReviewed byApproved byApproved date
19-02-20201.0Initial VersionUshaShailaSuresh Kumar19-02-2020

Acronym Used

AcronymExpanded Form
AMFAntares Management Forum
ISMSInformation Security Management System
CEOChief Executive Officer

Introduction

The quality of assessment of risks and recommendations to mitigate the same will determine the strength of the ISMS going forward. The purpose of this procedure is to provide the steps to be followed for seeking expert advice from external consultants for addressing specific information security requirements.  

ISO27001 Reference

  • A.6.1.4 Contact with special interest groups

Scope

This procedure is applicable when there is a need for information security advice, and in-house expertise is not available or in-house expertise, though available, but the required resources may not be utilized due to resource constraints.

Key Practices & Responsibility

The key practices and responsibilities are as follows:

Srl.Key PracticeResponsibility
Seeking Information Security AdviceAMF

Key Practice Details

Seeking Information Security Advice

The process flow depicted below   will be adopted for consulting information security experts.

{width="1.8229166666666667in" height="0.5833333333333334in"}

References

Srl.Document/Section Name
Procedure for Incident Management