Enforcement of Requirements in Connection with Information Security at Business Partners
More and more enterprises throughout the world use Information Security Management System on the basis of an international standard package of British origin, the ISO/IEC 2700x. Security policy and the necessary controls are specified on the evidence of business scopes and the strategy of the organization. The business partners can have access to some components of other’s information systems. This fact raises serious questions in the area of information security. The paper throws light on the required steps of risk management on the evidence of standard package.