ISO 27001 Certification

When talking with another person to ISO 27001 Certification, frequently I experience a similar issue: this individual thinks the standard will describe in detail everything they need to do – for example, how regularly they will need to perform backup, how distant their disaster recovery site should be, or even worse, which kind of innovation they must use for network protection or how they have to configure the router.

Why is ISO 27001 not prescriptive?

Let’s imagine that the standard recommends that you need to perform a backup every 24 hours – is this the correct measure for you? It might be, but believe me, numerous organizations these days will find this insufficient – the rate of change of their data is so quick that they need to do backup if not in real time, then at least every hour. On the other hand, there are still some organizations that would find the once-a-day backup too often – their rate of change is still very slow, so performing backup so often would be overkill.

The fact of the matter is– if this standard is to fit any type of a organization, at that point prescriptive methodology is not possible. Along these lines, it is simply unimaginable not only to characterize the backup frequency, yet in addition which technology to use, how to configure each device, etc.

Risk management is the focal thought of ISO 27001

Things being what they are, “For what reason would I need a standard that doesn't tell to me anything concretely?”

Because ISO 27001 Certification gives you a structure for you to choose on appropriate protection. A similar way, e.g., you can't duplicate a marketing campaign of another organization to your own, this same principle is valid for information security – you have to tailor it to your particular needs.

And the way ISO 27001:2013 Certification instructs you to achieve this tailor-made suit is to perform risk assessment and hazard treatment. This is nothing but a systematic overview of the bad things that can happen to you (assessing the risks), and then deciding which protections to execute to prevent those bad things from happening (treating the risks).

The entire thought here is that you should execute only those safeguards (controls) that are required because of the risks, not those that somebody believes are fancy; but, this logic also means that you should implement all the controls that are required because of the risks, and that you cannot avoid some simply because you don’t like them.

IT alone is not enough

If you work in the IT office, you are likely aware that most of the incidents are happening not because the PCs broke down, but because the clients from the business side of the association are utilizing the information systems in the incorrect manner.

And such wrongdoings cannot be prevented with technical safeguards only – what is also required are clear policies and procedures, training and awareness, legal protection, discipline measures, and so on. Real-life experience has proved that the more diverse safeguards are applied, the higher level of security is achieved.

And when you take into account that not all the sensitive information is in digital form (you probably still have papers with confidential information on them), the end is that IT safeguards are not enough, and that the IT department, although very important in an information security project, can’ run this kind of project alone.

Again, this fact that IT security is only 50% of information security is recognized in ISO 27001 – this standard tells you how to run the information security implementation as a company-wide project where not only IT, but also the business side of the organization, must take part.

Getting the top management aboard

But, ISO 27001:2013 Certification doesn’t stop with the implementation of various safeguards – its authors understood perfectly well that people from the IT department, or from other lower- or mid-level positions in the organization, cannot achieve much if the executives at the top don’t do something about it.

For instance, you may propose a new policy for the protection of confidential documents, but if your top management does not enforce such policy with all employees (and if they themselves do not comply with it), such a policy will never gain a foothold in your company.

So, ISO 27001 gives you a systematic checklist of what the top management must do:

  • set their business expectations (objectives) for information security
  • publish a policy on how to control whether those expectations are met
  • designate main responsibilities for information security
  • provide enough money and human resources
  • regularly review whether all the expectations were really met

Not allowing your system to deteriorate

If you work in a company for a couple of years or more, then you probably know how the new initiatives/projects work – at the beginning they look nice and shiny and everyone (or at least most of the people) are trying to do their best to make everything work. However, in time, the interest and the zeal deteriorate, and with them, everything related to such a project also deteriorates.

For instance, you may have had a classification policy that worked fine initially, but in time the technology changed, the organization changed and people changed, and if no one has cared to update the policy, it will become obsolete. And, as you are well aware, no one will want to comply with an obsolete document, meaning that your security will grow worse.

To prevent this, ISO 27001 has described a couple of methods that prevent such deterioration from taking place; even more, those methods are used to improve the security over time, making it even better than it was at the time when the project was at its highest. These methods include monitoring and measurement, internal audits, corrective actions, etc.

Visit : iso 27001 consultants egypt

No publications here.