Physical and Logical Security management organization model based on ISO 31000 and ISO 27001
Koldo Pecina, Ricardo Estremera, Alfonso Bilbao, Enrique Bilbao · 2011
This paper describes both the necessity of Physical and Logical Security management convergence and its implementation difficulty due to different organization models in most of the correspondent Security departments on enterprises and Administration organisms. This paper presents a methodology that makes it possible to comply with the ISO 31000 standard (for physical security) and ISO 27001 standard (for logical security) methodologies, analyzing simultaneously both information and physical assets. This paper presents an organization model proposal based on ISO 31000 standard (for physical security) and ISO 27001 standard (for logical security), and it integrates both models in the same company, being able to comply with both standards. The paper includes the proposed document structure for the model and a practical example of application.