Select your language

The 5 Big Myths About ISO 27001

Very often I hear comments about ISO 27001 and I don't know whether to laugh or cry. In fact, it's funny how people tend to make decisions about something they know very little about. Here are the most common misconceptions:

"The standard requires..."

"The standard requires keys to be changed every 3 months." "The standard requires that various suppliers be hired." "The standard requires that the alternate disaster recovery location be at least 50km away from the main location." Is that so? The standard says nothing of all this. Unfortunately, this is the kind of false information I usually hear. Many times, people confuse best practices with requirements of the standard, but the problem is that not all security rules are applicable to all types of organizations. And those who argue that this is established in the norm, have hardly ever read it.

"We'll let the IT department handle it"

This is the management's favorite: "Information security is all about information technology, isn't it?" Well, not exactly. The most important aspects of information security include not only IT measures, but also organizational issues and human resource management, which, in general, are outside the scope of the IT department. See also Information Security or IT Security.

"We will implement it in a few months"

- Publicidad -

It might be possible for you to implement ISO 27001 in two or three months, but it won't work; you will only get a bunch of policies and procedures that no one will take into account. Implementing information security means you have to implement changes, and this takes time.

Needless to say, you should implement only the security controls you really need, and analyzing what is necessary takes time; it's called risk assessment and treatment.

"This standard is nothing more than documentation"

Documentation is an important part of implementing ISO 27001, but it is not an end in itself. The most important thing is that you carry out your activities safely, and the documentation is there precisely to help you. In addition, the logs you generate will help you measure whether you achieved your information security goals and allow you to correct those activities that have not.

"The only benefit of the standard is to gain a marketing advantage"

"We're doing this just to get the certificate, aren't we?" Well, this is (unfortunately) the way 80 percent of companies think. I am not trying to discuss here whether or not ISO 27001 should be used for promotional and sales purposes, but it can also obtain other very important benefits; like preventing the WikiLeaks thing from happening to him. See also Four Key Benefits of ISO 27001 Implementation and Lessons Learned from WikiLeaks: What Exactly Is Information Security?

The important thing here is that you first have to read ISO 27001 to be able to give an opinion about it, or, if you find it too boring (I admit it is) to read it, consult someone who really knows it. And try to see other advantages besides advertising. That is, increase your chances of making a profitable investment in information security.


Author: Dejan Kosutic
Source: Blog iso27001standard.com

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter