Management Systems

Bill Wood Associates has recently completed the implementation of ISO 9001:2000 for An Garda Sciochána - central vetting unit.

Information Security Management Systems ISO

All businesses obtain, store and use a considerable amount of information, without which they would not be able to function. This information includes, client information, product data, manufacturing / service records, financial records and staff details etc.

All this information needs to be controlled to ensure it is maintained current and is updated as required. This information needs to be safely held, with adequate back-up systems in the event of a disaster (fire, flood etc.). It is also essential that the data is legally held. Compliance with the Data Protection Act is mandatory, and failure to comply will result in prosecution.

An international standard is available to help organisations develop suitable management systems to safeguard the information. In addition to the security of the information, the introduction of easy access to the internet and e-mail systems by staff poses an additional problem for managers. There is a need to develop and implement policies relating to access to the web and the use of e-mail.

The Data Protection Act puts a legal obligation on the organisation to ensure all personal information is legally held, is only used for the purpose specified and is secure. Without a process to control the data held it becomes more and more difficult to ensure legal compliance and reduce the risk of information being lost stolen or corrupted.

What would happen to your business if your competitors gained access to client information, product details, costing's etc?