the Home of DNA testing

DNA relationship testing since 1987

ISO27001

ISO/IEC 27001 is the formal set of specifications against which organizations may seek independent certification of their Information Security Management System (ISMS). ISO/IEC 27001 specifies requirements for the establishment, implementation, monitoring and review, maintenance and improvement of a management system - an overall management and control framework - for managing an organization's information security risks. The standard covers all types of organizations (e.g. commercial enterprises, government agencies and non-profit organizations) and all sizes from micro-businesses to huge multinationals. Bringing information security under management control is a prerequisite for sustainable, directed and continuous improvement. An ISO/IEC 27001 ISMS therefore incorporates several Plan-Do-Check-Act (PDCA) cycles: for example, information security controls are not merely specified and implemented as a one-off activity but are continually reviewed and adjusted to take account of changes in the security threats, vulnerabilities and impacts of information security failures, using review and improvement activities specified within the management system. According to JTC1/SC27, the ISO/IEC committee responsible for ISO27k and related standards, ISO/IEC 27001 “is intended to be suitable for several different types of use, including:
  • Use within organisations to formulate security requirements and objectives;
  • Use within organisations as a way to ensure that security risks are cost-effectively managed;
  • Use within organisations to ensure compliance with laws and regulations;
  • Use within an organisation as a process framework for the implementation and management of controls to ensure that the specific security objectives of an organisation are met;
  • The definition of new information security management processes;
  • Identification and clarification of existing information security management processes;
  • Use by the management of organisations to determine the status of information security management activities;
  • Use by the internal and external auditors of organisations to demonstrate the information security policies, directives and standards adopted by an organisation and determine the degree of compliance with those policies, directives and standards;
  • Use by organisations to provide relevant information about information security policies, directives, standards and procedures to trading partners and other organisations that they interact with for operational or commercial reasons;
  • Implementation of a business enabling information security; and
  • Use by organisations to provide relevant information about information security to customers."
Cellmark now transmits customer information in a secure format by means of password protected pdf files. For additional information please visit http://www.iso27001security.com/html/27001.html
Court approved DNA testing

Advice for your clients
View and download a pdf version of our Paternity Testing brochure.

How to choose a paternity tester
The key points you and your clients need to consider when choosing which company to use.

Impact of the Human Tissue act
Due to finally come into force in April 2006 the issue of fully consentual testing is crucial.

Immigration Testing
We are contracted to the Foreign and Commonwealth Office for their DNA relationship testing and we also act on behalf of private individuals. For further information please contact us on 01235 528000.

 

Need some advice on DNA testing?
Contact us using our confidential SMS service. Just enter your mobile phone number and your question and we will answer your question.