| One of the most widely referenced and often discussed security models is Information Technology – Code of Practice for Information Security Management, which was originally published as British Standard BS 7799. The purpose of ISO/IEC 17799 is to “give recommendations for information security management for use by those who are responsible for initiating, implementing or maintaining security in their organization. It is intended to provide a common basis for developing organizational security standards and effective security management practice and to provide confidence in inter-organizational dealings.” The implementation stage is a very important and critical stage to ensure that the Quality Management system during the course of implementation, the organization could face some problems. However, appropriate remedial measures or the corrective actions should be taken. Briefly, they can be summarized as under: |