top of page

Using ISO 27001 to protect you in a threat-filled world

  • Mar 9, 2022
  • 3 min read

Updated: Mar 15, 2022

The ISO 27001 standard covers many aspects of data security, providing sufficient information for the implementer to understand the major data security issues and what to do about them.


Information security is a complex issue and deals with the confidentiality, integrity and availability of data. IT governance is even more complex, and in information security terms one has to think in terms of the whole enterprise, the entire organisation, which includes all the possible combinations of physical and cyber assets, all the possible combinations of intranets, extranets and internets, and which might include an extended network of business partners, vendors, customers and others.


Fortunately help is at hand through this maze of issues, through the process of implementing internationally recognised best practice in information security, as captured in ISOIEC 27002:2013 and, finally, achieving certification to ISO/IEC 27001:2013, the world's formal, public, international standard for effective information security management.


The ISMS standard is not geographically limited (eg to the United Kingdom, or Japan or the United States), nor is it restricted to a specific sector (eg the Department of Defence or the software industry), nor is it restricted to a specific product (such as an ERP system, or Software as a Service).


This standard covers many aspects of data security, providing sufficient information for the implementer to understand the major data security issues and what to do about them - and, above all, what steps and systems are necessary for the achievement of independent certification of the organisation's ISMS to ISO27001.


This standard is of particular benefit to board members, directors, executives, owners and managers of any business or organisation that depends on information, that uses computers on a regular basis, that is responsible for personal data or that has an internet aspect to its strategy. It can equally apply to any organisation that relies on the confidentiality, integrity and availability of its data.


Information security is a key component of IT governance. As information technology and information itself become more and more the strategic enablers of organisational activity, so the effective management of both and information assets becomes a critical strategic concern for boards of directors.


This standard will enable directors and business managers in organisations and enterprises of all sizes to ensure that their IT security strategies are coordinated, coherent, comprehensive and cost-effective, and meet their specific organisational or business needs.


Organisations should always ensure that any processes they implement are appropriate and tailored for their own environment. There are four reasons for this:


  • Policies, processes and procedures should always reflect the style, and the culture, of the organisation that is going to use them. This will help their acceptance within the organisation.


  • The processes and procedures that are adopted should reflect the risk assessment carried out by the organisation's specialist security adviser. While some risks are common to many organisations, the approach to controlling them should be appropriate to, and cost-effective for, the individual organisation and its individual objectives and operating environment.


  • It is important that the organisation understands, in detail, its policies, processes and procedures. It will have to review them after any significant security incident and at least once a year. The best way to understand them thoroughly is through the detailed drafting process.


  • Most importantly, the threats to an organisation's information security are evolving as fast as the information technology that supports it. It is essential that security processes and procedures are completely up to date, that they reflect current risks and that, in particular, current technological advice is taken.


 
 
 

Recent Posts

See All

Comments


bottom of page