Select your language

Why should IT security be certified under ISO 27001?

Gabriel Marcos, from Global Crossing, explains in this note to iProfesional.com the need to check the strength of companies' systems

When explaining why to certify an international standard focused on the management of risks associated with information security, such as the ISO 27000 series of standards and in particular its certifiable chapter, that is, the ISO 27001 standard, one could start by justifying its position from different angles.

For example, analyzing

Gabriel Marcos, from Global Crossing, explains in this note to iProfesional.com the need to check the strength of companies' systems

When explaining why to certify an international standard focused on the management of risks associated with information security, such as the ISO 27000 series of standards and in particular its certifiable chapter, that is, the ISO 27001 standard, one could start by justifying its position from different angles.

For example, analyzing investment returns in different implementation scenarios, cost advantages, brand recognition, regulatory aspects, relationship between the international standard and other local regulations, showing the synergy between different management systems that are probably already implemented or on track to be implemented as ISO 9000, ISO 14000 or ISO 20000 among others.

- Publicidad -

We could also start with something much more complex: detailing what are the risks that the standard would help mitigate, from which all other aspects are deduced much more simply.

But why are the risks so difficult to describe? Precisely because they do not stand still, that is, they constantly evolve.

They are always latent, although they are not so easily seen.

In this way, if today, as the standard suggests, we made a list of assets, detailed all the threats that affect them, the vulnerabilities associated with those threats, and finally made an assessment of the resulting risks based on their impact and probability of occurrence, we could ensure that the next day, that valuation would be outdated.

And it is for this reason that the standard begins by defining the management system that will serve as the basis for managing risks, before even beginning to touch on issues related to safety: systematizing the discovery, treatment and mitigation of risks, and sustaining these activities over time, is a necessary condition to be considered "minimally safe", with all the difficulties (and justified criticism) that expressing it in that way could entail.

After having implemented a risk management system, with all the aforementioned considerations, including periodic reviews of a Security Committee that allocates resources, verifies the implementation of controls, promotes continuous improvement of processes, and adjusts organizational policies that complement security measures by incorporating them into a training and awareness plan for all actors that interact with company information, we'll have just a glimpse of what it means to have ISO 27001 in an organization.

This standard relates to all areas and processes of the company, including Human Resources, Technology and Legal, also producing one of the most important cultural (and political) changes of the last 10 years in organizations in general, which is the separation of functions between the areas of Technology and Security, which should ideally report directly to the CEO and / or the Board.

- Publicidad -

But the objective of the note is not only to talk about ISO 27001, but also about why it is convenient to certify the implementation of the standard: is it that just implementing it is not enough?

From my experience, certification adds a fundamental component, which are external audits: these are carried out (ideally) by professional auditors who day by day gain experience in auditing organizations in different markets, countries and types of business, providing objectivity to the management system implemented through the observations and non-conformities they detect.

In an ISO management system, it is desirable that aspects appear to improve, since otherwise for what one would like to have a system based on continuous improvement, and when only internal audits are carried out, we are missing an unbeatable opportunity to validate the effectiveness of risk management.

Now we can go back to the beginning of the note and list all the advantages that we will surely have after obtaining the certification, being aware that behind a certificate, there are many more benefits for the organization although sometimes: "the essential is invisible to the eyes.

Gabriel Marcos is Product Manager at Global Crossing

Source: iProfesional

- Publicidad -

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Thanks to technological evolution, today there are smart readers with the capacity to process credentials, store information and even operate locks autonomously. This has led many organizations to...

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Almacenes El Rey is a rapidly expanding department store, with 18 branches nationwide and more than one million customers each year. Thanks to the Avigilon Unity Video solution, the retail chain...

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Latin America. Johana Arias, an executive at Milestone Systems, discusses how the integration of AI, natural language, and open platforms are transforming video into actionable insights for...

Anti-intrusion system described as one of Ajax's largest in South America

Anti-intrusion system described as one of Ajax's largest in South America

Argentina. The Bayron company installed a protection system with more than 85 Ajax wireless devices in the new branch of Autos del Sur S.A., Toyota's official dealership in the country.

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Mexico. Manuel Carlos, an executive at Hanwha Vision, details how the company is revolutionizing electronic security by consolidating generative artificial intelligence and processing at the edge.

Prosegur presents new capabilities in cybersecurity and automation

Prosegur presents new capabilities in cybersecurity and automation

International. Prosegur Security has created two new modules, xCope and xEcute, which aim to provide companies and organizations with a new corporate digital surveillance service and another for...

Access and video platform

Access and video platform

Johnson Controls Designed to take the complexity out of legacy systems, the latest version of C•CURE IQ helps organizations achieve faster response, simplify workflows, and turn safety data into...

SIA presents the new directives of its International Relations Committee

SIA presents the new directives of its International Relations Committee

Latin America. Mariana Ramírez is the new president of the International Relations Committee of the Security Industry Association (SIA), while Vanesa Cabral assumed the role of vice president.

Access management and security in stadiums during the World Cup

Access management and security in stadiums during the World Cup

International. With the World Cup underway, stadium operation and the management of credentials and critical assets become key factors in ensuring security in high-demand environments.

Jovicard modernizes its headquarters with HID access control technology

Jovicard modernizes its headquarters with HID access control technology

Brazil. Jovicard, which specializes in physical access control, secure identity, biometrics and integrated electronic security, completed the modernization of its corporate headquarters with trusted...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter