ERM Practical Connection Activity
1
Addressing Information Security Risks by Adopting Standards
Manchoopaporn Boonchoo
University of the Cumberlands.
Enterprise Risk Management
ITS 835- 40
Dr. Abiodun Adeleke (Abbey)
06/13/2021
Introduction
Having worked for Jira Software, I believe the ISO 27001 has worked well for the company as they have maintained certification and compliance with standards which have been instrumental for the company to address regulatory and customers’ contractual obligations. The certification has provided the customers with an autonomous substantiation of the company’s information security and privacy practices. ISO 27001 has become one of the earliest and best known standard for Information Security Management Systems (ISMS) (Culot et al., 2021). Hence, in Jira's information security management system, all the control requirements have been added to the statement of applicability as defined within ISO 27001 standard. The standard set within the ISO framework to ensure that an organization can provide assurance that it can protect the data that people have entrusted them with and can counter cyberattacks that could compromise data. (Lopes et al., 2019). To maintain certification, the company is subjected to independent audit every 3 years to ensure standards are maintained. Jira ISO 27001 certification encompasses information security policies, asset management, access control, business continuity, compliance, organization of information security, and physical and environmental security.
Effectiveness of ISM Framework
Jira uses the cross-functional approach to governing data privacy. That is, the privacy governance is applied across the organization to include the data of both the customers, vendors and employees. The company has a defined structure whereby the legal team consists of a senior director who is the head of Privacy and Law Enforcement compliance and directly reports to the General Counsel (Culot, et al., 2021). The organization also has a privacy Engineering Team that collaborates with the Legal Team and the product counsel in designing products from the start-up to finish to protect customer privacy and ensure that the data is protected and remains in control of the company at all times. This involves a strong process that ensures that data collected is used as intended and as required by law. The company also has a privacy steering committee that is tasked with setting the privacy standards for the Jira team and it also addresses privacy compliance problems for decisions. Furthermore, the audit and finance committee of the Board of Directors plays an important role in doing the oversight work and monitoring privacy and data security (Al-Ahmad & Mohammad, 2013).
Notably, the company policy requires all the employees to undergo annual training on Business Conduct to remind and emphasize their commitment to respect of human rights and maintaining ethical business practices characterized by honesty and compliance with the laws and regulations. Jira considers privacy training as a critical element of the Business Conduct Training. It is essential for every employee with access to customer data and personal information to have an additional privacy training course on the subject on a bi-annual basis to remain updated on the laws concerning the EU General Data Protection Regulation (Goddard, 2017). Furthermore, there is other training provided to employees who are in charge of handling large amounts of sensitive data. The organization undergoes a Privacy Impact Assessment annually for its major products and services which are integrated into the new products (Steglich et al., 2020). As an international company, Jira goes a step further to engage with different civil society representatives from around the world to address the issues related to data privacy by designing and encryption.
Jira ISO 27001 Framework
The services that are covered by ISO 27001 consist of the Jira Business Chat, Cloud storage, managed Jira IDs, Jira school manager, and the Jira Push Notifications services. The company has remained committed to human rights and is guided by the Human Rights Policy which outlines how company should treat customers, employees, and business partners at all levels of the supply chain that is aided by ISO 27001 framework (Al-Ahmad & Mohammad, 2013). The company makes products adhering to the principle of privacy by default and it only collects the required data necessary to provide to the users of its services and products. When data is collected by the company, it is retained only to fulfill the objective for which it was collected and that includes describing the privacy policy as necessitated by the law. Besides, Jira had deployed the mechanism where the customers are allowed to choose what they would like to share like Jira Music with other apps.
Frameworks Based on Research to address the risks
Another framework that would be suggested is Control Objectives for Information and
Related Technology (COBIT). The COBIT framework has been used to facilitate needed alignment between the business and the information technology employed to enhance the operations of organizations. It provides the IT governance framework necessary to govern how a company employs resources to safeguard information. It will ensure that the company will have the organization structure to create IT policies and procedures and inform on the company's management of compliance (Al-Ahmad & Mohammad, 2013). COBIT can be used to standardize the cyber activities undertaken by a company, ensuring that the company can use technology effectively in meeting demands without having data compromised within the systems company have employed to execute the functions.
The data security and incident response framework have been strictly enforced to safeguard the customer’s privacy. This implies that the company employs access management and the access control appropriate with risk to data in ensuring accessibility of data conforms to the needs of the business. The Jira platform security is essential for giving more details to the designer of operating systems. This is similar with Apple security which comprises of the iOS, iPadOS, macOS, and watchOS that protects the security of the customers (Novac et al., 2017). For instance, when the organization realizes a problem with data security that may affect the customer’s data and information, it deploys a dedicated team to investigate the issue and apply the necessary steps. If there is a breach in data, one of the steps taken is to update the software immediately. Therefore, Jira is aware of such problems and it ensures that it follows the rule of law where applicable without undue delay.
For privacy policy updates, the company post updates on its web page in advance to advise the user on the expected changes. Jira does not share its user information with third parties where the information is requested with no legal basis this is because of the company's commitment to transparency on private requests for user information (Lopes et al., 2019). For the de-identification of the personal data, company removes all the elements and identifiers associated with personal data. However, adherence to the company de-identification is subjected to review under the privacy compliance audit and the verification team.
Conclusion and Recommendation
Overall, information security management is considered as the set of policies with management and information and communication technology risks. Adoption of an IT Standards framework will ensure that the data at the disposal of an organization are used effectively. Therefore, Jira has successfully implemented ISO 27001 to comprehensively address information security problems. Jira Software uses the certification of ISO 27001 standards to assure they address all the security obligations of their customers. The management team ensures there is total commitment and adequate resources distributed to ensure information security management systems (ISMS) are developed to reduce the risk of the organization employees, partners, and other stakeholders. An effective ISMS ensures that an organization has a framework to identify a problem and protect its information from being handled by unauthorized people who may compromise the data. Furthermore, Jira should continue to review how to enhance its approach to information security which will ensure an effective response to the ever-evolving business environment and the threats the company might face. Hence recommendations to the organization should seek to introduce a consistent approach to security training that will put all members on the same page to understand their responsibilities. They should also conduct a risk assessment to ensure all the treatment plans have been established and achieved the organization threshold. Also, Jira should review the bi-annual assessment to ensure they achieve the effectiveness of the information security management system and ensuring resources have been committed for full operation and improvement of the management system.
References
Al-Ahmad, W., & Mohammad, B. (2013). Addressing information security risks by adopting standards. International Journal of Information Security Science, 2(2), 28-43.
https://ijiss.org/~ijissorg/ijiss/index.php/ijiss/article/viewFile/20/pdf_5
Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2021). The ISO/IEC 27001 information security management standard: literature review and theory-based research agenda. The TQM Journal, 33(7), 76-105.
https://doi.org/10.1108/TQM-09-2020-0202
Goddard, M. (2017). The EU General Data Protection Regulation (GDPR): European regulation that has a global impact. International Journal of Market Research, 59(6), 703-705.
https://doi.org/10.2501/IJMR-2017-050
Lopes, M., Guarda, T. & Oliveira, P. (2019). How ISO 27001 Can help achieve GDPR
compliance. In 2019 14th Iberian Conference on Information Systems and Technologies (CISTI), (pp. 1-6).
https://ieeexplore.ieee.org/document/8760937?arnumber=8760937
Novac, O. C., Novac, M., Gordan, C., Berczes, T., & Bujdosó, G. (2017, June). Comparative study of Google Android, Apple iOS and Microsoft Windows phone mobile operating systems. In 2017 14th International Conference on Engineering of Modern Electric Systems (EMES), 154-159.
https://doi.org/10.1109/EMES.2017.7980403
Steglich, C., Majdenbaum, A., Marczak, S., & Santos, R. (2020, March). A Study on Organizational IT Security in Mobile Software Ecosystems Literature. In 2020 IEEE International Conference on Software Architecture Companion (ICSA-C), 234-24.
https://doi.org/10.1109/ICSA-C50368.2020.00047