SlideShare a Scribd company logo
Governance, Risk & Compliance
Using
ISO 27001, ISO 20000 & ISO 22301
Sharing the Leading Best Practices in One Project
Agenda
 Introduction
 The components of the Good Governance
– ISO 27001- Protecting the Information
– ISO 20,000 – Ensuring the Best IT Service
Management
– ISO 22301 – Ensuring the Continuity of the
Business
 Checklist
 Conclusion
GRC
Importance of GRC
 GRC Projects are must for various reasons
 GRC has Crossed V1 Speed.
Three Important Components of IT
What is Governance?
What is the Solution?
Explore Standards
The Solution
9
Gartner Hype Cycle
10
Managing the Expectations
11
Gartner’s View
Selecting Top 3 Standards for
Comprehensive Coverage
Comprehensive Governance
Coverage
Information
Security
ISO 27001
(IT) Service
Management
System
ISO 20,000
Business
Continuity
ISO 22301
The Must have Standard.
Information Security and
ISO 27001
What is ISO 27001?
 ISO 27001 is the Standard of Information Security
 Two Parts
– ISO 27001: Specifications
– ISO 27002: Code of Practices
 Uniqueness of ISO 27001
– Standard
– 114 Annex A Controls
ISO 27001
ISO 27000 Series..
 Anxiously Waiting for…
– 27000: Fundamentals and Vocabulary
– 27001: ISMS Auditable and certifiable requirements
– 27002: Replaced ISO 17799
– 27003: ISMS Implementation Guidelines
– 27004: ISMS Measurement
– 27005: ISMS Risk Management
– 27006: Guide to the certification/registration process for accredited ISMS
certification/registration bodies
– 27007: Guidance for those auditing Information Security Management
Systems against ISO 27001
– 27031: Information security management guidelines for
telecommunications
ISO 20,000 for
(IT) Service Management System
ISO 20000
ITIL V3.0
ITIL
 It is all about the ‘Service’
 IT is recognized as ‘Service Provider’
– To be more specific IT is Service Provider to it’s
customer Business Users
Based on Deming Cycle
Deming Cycle
 William Edwards Deming
– (October 14, 1900 – December 20, 1993) was
Statistician.
– Best known for his work in Japan.
– From 1950 onward he taught top management
how to improve
 Design (and thus service),
 Product quality,
 Testing and s
ISO 22301
for
Business Continuity Management
Importance of BCM
What is a Disaster?
Storage Recovery Strategy
In Summary….
Fast Track Implementation
No Standardization is No Excuse
Thank You!

More Related Content

PPT
Overview of ISO 27001 ISMS
PDF
Select information security system 2015en
PDF
It security iso 27001
PPTX
Use_of_ISO_in_IT_Presentation_Enhanced.pptx
PPTX
FRAMEWORKS AND STANDARDS-GRC,GDPR,SOX,PCI DSS,SOX,ISO
PDF
Whitepaper iso 27001_isms | All about ISO 27001
PPTX
ISO_in_IT_Presentation for understanding the use of ISO in it
PDF
NQA ISO 27001 Implementation Guide
Overview of ISO 27001 ISMS
Select information security system 2015en
It security iso 27001
Use_of_ISO_in_IT_Presentation_Enhanced.pptx
FRAMEWORKS AND STANDARDS-GRC,GDPR,SOX,PCI DSS,SOX,ISO
Whitepaper iso 27001_isms | All about ISO 27001
ISO_in_IT_Presentation for understanding the use of ISO in it
NQA ISO 27001 Implementation Guide

Similar to GRC2-KSA.ppt (20)

PDF
NQA - ISO 27001 Implementation Guide
PDF
NQA Your Risk Assurance Partner
PPTX
Standardization of IT Processes
PDF
NQA-ISO-27001-Implementation-Guide and implementation procedure book
PDF
NQA-ISO-27001-Implementation-Guide.pdf..
PDF
Cyber Security Management
PPT
ISMS Requirements
PPTX
ISO 27001 Training Module 1 - An Introduction to ISO 27001.pptx
PDF
PDF
ISO 27001 is the commonly used standard for ISMS implementation and certifica
PPTX
2017 QA Forum presentation Igor Stevkosvski CIS.pptx
PPTX
the role of 27001 in cybersecurity pp.pptx
PDF
NQA Your Complete Guide to ISO 27001
PDF
NQA Your Complete Guide to ISO 27001
PDF
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
PDF
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
PPTX
Presentaion.pptx
PPTX
Experience from Implementation of ISO 20000
PDF
PPT
4 System For Information Security
NQA - ISO 27001 Implementation Guide
NQA Your Risk Assurance Partner
Standardization of IT Processes
NQA-ISO-27001-Implementation-Guide and implementation procedure book
NQA-ISO-27001-Implementation-Guide.pdf..
Cyber Security Management
ISMS Requirements
ISO 27001 Training Module 1 - An Introduction to ISO 27001.pptx
ISO 27001 is the commonly used standard for ISMS implementation and certifica
2017 QA Forum presentation Igor Stevkosvski CIS.pptx
the role of 27001 in cybersecurity pp.pptx
NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
Presentaion.pptx
Experience from Implementation of ISO 20000
4 System For Information Security
Ad

More from ssuser3901ab (11)

PDF
Appendix 1 - Strategic Asset Management Plan-property.pdf
PPT
Pertemuan2.ppt
PPT
Pertemuan1.ppt
PPT
Pertemuan3.ppt
PPT
Pertemuan4.ppt
PPT
Pertemuan5.ppt
PPT
Pertemuan6.ppt
PPT
Pertemuan7.ppt
PDF
IBM Maximo AM-USER.pdf
PPTX
MOT-ok.pptx
PPT
Pertemuan1OK.ppt
Appendix 1 - Strategic Asset Management Plan-property.pdf
Pertemuan2.ppt
Pertemuan1.ppt
Pertemuan3.ppt
Pertemuan4.ppt
Pertemuan5.ppt
Pertemuan6.ppt
Pertemuan7.ppt
IBM Maximo AM-USER.pdf
MOT-ok.pptx
Pertemuan1OK.ppt
Ad

Recently uploaded (20)

PDF
.pdf is not working space design for the following data for the following dat...
PPTX
STUDY DESIGN details- Lt Col Maksud (21).pptx
PPT
Chapter 3 METAL JOINING.pptnnnnnnnnnnnnn
PDF
Mega Projects Data Mega Projects Data
PPTX
climate analysis of Dhaka ,Banglades.pptx
PPT
Miokarditis (Inflamasi pada Otot Jantung)
PPTX
Introduction to Knowledge Engineering Part 1
PDF
Fluorescence-microscope_Botany_detailed content
PPT
Quality review (1)_presentation of this 21
PPTX
mbdjdhjjodule 5-1 rhfhhfjtjjhafbrhfnfbbfnb
PDF
TRAFFIC-MANAGEMENT-AND-ACCIDENT-INVESTIGATION-WITH-DRIVING-PDF-FILE.pdf
PPTX
Computer network topology notes for revision
PPTX
Introduction to Basics of Ethical Hacking and Penetration Testing -Unit No. 1...
PPTX
05. PRACTICAL GUIDE TO MICROSOFT EXCEL.pptx
PPTX
Business Ppt On Nestle.pptx huunnnhhgfvu
PPTX
ALIMENTARY AND BILIARY CONDITIONS 3-1.pptx
PDF
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
PPTX
Acceptance and paychological effects of mandatory extra coach I classes.pptx
PDF
Launch Your Data Science Career in Kochi – 2025
PDF
Galatica Smart Energy Infrastructure Startup Pitch Deck
.pdf is not working space design for the following data for the following dat...
STUDY DESIGN details- Lt Col Maksud (21).pptx
Chapter 3 METAL JOINING.pptnnnnnnnnnnnnn
Mega Projects Data Mega Projects Data
climate analysis of Dhaka ,Banglades.pptx
Miokarditis (Inflamasi pada Otot Jantung)
Introduction to Knowledge Engineering Part 1
Fluorescence-microscope_Botany_detailed content
Quality review (1)_presentation of this 21
mbdjdhjjodule 5-1 rhfhhfjtjjhafbrhfnfbbfnb
TRAFFIC-MANAGEMENT-AND-ACCIDENT-INVESTIGATION-WITH-DRIVING-PDF-FILE.pdf
Computer network topology notes for revision
Introduction to Basics of Ethical Hacking and Penetration Testing -Unit No. 1...
05. PRACTICAL GUIDE TO MICROSOFT EXCEL.pptx
Business Ppt On Nestle.pptx huunnnhhgfvu
ALIMENTARY AND BILIARY CONDITIONS 3-1.pptx
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
Acceptance and paychological effects of mandatory extra coach I classes.pptx
Launch Your Data Science Career in Kochi – 2025
Galatica Smart Energy Infrastructure Startup Pitch Deck

GRC2-KSA.ppt