Select your language

Why should IT security be certified under ISO 27001?

Gabriel Marcos, from Global Crossing, explains in this note to iProfesional.com the need to check the strength of companies' systems

When explaining why to certify an international standard focused on the management of risks associated with information security, such as the ISO 27000 series of standards and in particular its certifiable chapter, that is, the ISO 27001 standard, one could start by justifying its position from different angles.

For example, analyzing investment returns in different implementation scenarios, cost advantages, brand recognition, regulatory aspects, relationship between the international standard and other local regulations, showing the synergy between different management systems that are probably already implemented or on track to be implemented as ISO 9000, ISO 14000 or ISO 20000 among others.

We could also start with something much more complex: detailing what are the risks that the standard would help mitigate, from which all other aspects are deduced much more simply.

But why are the risks so difficult to describe? Precisely because they do not stand still, that is, they constantly evolve.

- Publicidad -

They are always latent, although they are not so easily seen.

In this way, if today, as the standard suggests, we made a list of assets, detailed all the threats that affect them, the vulnerabilities associated with those threats, and finally made an assessment of the resulting risks based on their impact and probability of occurrence, we could ensure that the next day, that valuation would be outdated.

And it is for this reason that the standard begins by defining the management system that will serve as the basis for managing risks, before even beginning to touch on issues related to safety: systematizing the discovery, treatment and mitigation of risks, and sustaining these activities over time, is a necessary condition to be considered "minimally safe", with all the difficulties (and justified criticism) that expressing it in that way could entail.

After having implemented a risk management system, with all the aforementioned considerations, including periodic reviews of a Security Committee that allocates resources, verifies the implementation of controls, promotes continuous improvement of processes, and adjusts organizational policies that complement security measures by incorporating them into a training and awareness plan for all actors that interact with company information, we'll have just a glimpse of what it means to have ISO 27001 in an organization.

This standard relates to all areas and processes of the company, including Human Resources, Technology and Legal, also producing one of the most important cultural (and political) changes of the last 10 years in organizations in general, which is the separation of functions between the areas of Technology and Security, which should ideally report directly to the CEO and / or the Board.

But the objective of the note is not only to talk about ISO 27001, but also about why it is convenient to certify the implementation of the standard: is it that just implementing it is not enough?

From my experience, certification adds a fundamental component, which are external audits: these are carried out (ideally) by professional auditors who day by day gain experience in auditing organizations in different markets, countries and types of business, providing objectivity to the management system implemented through the observations and non-conformities they detect.

- Publicidad -

In an ISO management system, it is desirable that aspects appear to improve, since otherwise for what one would like to have a system based on continuous improvement, and when only internal audits are carried out, we are missing an unbeatable opportunity to validate the effectiveness of risk management.

Now we can go back to the beginning of the note and list all the advantages that we will surely have after obtaining the certification, being aware that behind a certificate, there are many more benefits for the organization although sometimes: "the essential is invisible to the eyes.

Gabriel Marcos is Product Manager at Global Crossing

Source: iProfesional

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter