Table of Contents
This updated guide examines Information Security -- Where to Start? and organizes the essential facts, background, and practical takeaways in clear American English.

Information security policy is organized in a pyramid model. This organization helps leaders manage information security quality in a scientific and effective way. On the top of the pyramid describes the policies applied in the organization. Why should we set this policy? Scope and object of policy impact?. There is no one policy that applies to all units. In an organization with many parts, each part has different functions, different characteristics and organization of information. The business department has its own system design model with the database bearing business characteristics, production department, research department also has its own system and database structure. Information security awareness level is also very different. Therefore, when establishing policies, managers need to clearly define the purpose of the established policy, the object of enforcement, the scope of impact. The second layer on the model describes the rules and regulations for implementing policies. What do we have to do to implement policies? The system of traffic safety rules is shown in 10 major areas including regulations from organizations, people, physical security to information security technical tools. Rules are built on the model. IT standards of the organization and embody the specificity of the organization. Through the implementation of the rules, it is possible to assess the quality of information security of an organization through auditing (Audit). The third layer is the final layer of the model. These are the processes and solutions that support the implementation of the above rules and regulations. It answers the question of how to enforce the above rules? Information security administrators (CSOs) and IT administrators set up these processes and disseminate them to all employees in the organization, for example 'Password change process', 'Installation procedures' anti-virus programs, anti-malicious programs' etc. These processes may involve many different policies and users. What are the benefits of applying ISO 17799 to the organization? The application of ATTT standards according to ISO 17799 raises awareness for employees on workplace safety. Build a safe environment, immunity to risks, reduce the risks posed by humans. The ISO 17799 standard sets out the general principles in the design process, builds a scientific information system, making the management of the system brighter, safer and more transparent. We build a 'Secure People Wall' in the organization. A safe and clean information environment will have a significant impact on reducing the physical cost of investment for ATTT, which is inherently expensive. In the long run, getting ISO 17799 certification is a convincing affirmation to partners, customers about a safe and clean information environment. Create favorable conditions for the integration of a healthy information environment. This will strongly impact the competitive advantage of the organization. Human resource training problem
According to IDG in 2006, there will be a new profession in the field of IT - information security profession. CSO title (Chief Security Officer) becomes familiar in IT field. Updating and improving knowledge of ATTT and awareness of its role in IT system is a very important and urgent thing because considering human actions is the decisive factor. Although safety awareness is widely known, human factors are often less interested in by organizations. For executives, they need a safety policy and an awareness program as well as a quality assessment of safety, but unfortunately there are not many solutions that really care about how to strengthen solidity for this inherently weak link in the chain of ATTT. Today, a number of businesses in Vietnam have made positive changes in the awareness of safety and hygiene. They are willing to invest human resources training budget to create a solid foundation of awareness and knowledge of ATT for employees of the enterprise. Typically, Dong Nai Department of Science and Technology, Bao Minh Insurance Company, Fujitsu Vietnam, Asia Bank. In addition, there are still many businesses, especially small and medium enterprises, who have not yet approached and fully understand the importance of establishing safety policies and managing quality standards of ATTT according to ISO 17799. strange and new to them. Information security in general and quality assessment of information security in particular is still a new issue in Vietnam. Hope the article helps managers and policy makers have more information about quality control of traffic safety as well as approach to information security issues - a very sensitive issue at the moment. At the same time, the article also clarifies the role of people - the weakest stage in security information as well as the importance of human resource training in this area
Dr. Dao The Long - Misoft ISTC Email: tan.document@gmail.com
FAQ
What is Information Security -- Where to Start about?
It provides a structured overview of information, explains the main context, and highlights practical takeaways for readers.
Why does this topic matter?
Understanding the main concepts helps readers evaluate the issue, avoid common mistakes, and make better-informed decisions.
How should readers use this information?
Use the guidance as a practical starting point, confirm details that may have changed, and follow current product, safety, or security recommendations.
Reader Comments 0
Sign in with email or Google to join the discussion.