PT XYZ is a provider of document management services, in cooperation with local/foreign banks. Documents containing customer information, so that information security should be set to provide services that meet information security criteria. Information security audit results showed weak information security, less monitored and evaluated. This research focuses on information security audit in accordance with ISO 27001 to provide comprehensive information security policies and procedures. The methodology used are assessment, risk analysis and impact, controls selection and recommendation of policies and procedures. Audit results showed a gap between policies and procedures that apply in PT XYZ with ISO 27001.
Copyrights © 2013