During this briefing I will discuss what the ISO 27001 is, how an Information Security
Management System can be established, the benefits of being certified according to that standard, and
how an organization such as Padgett Beale can obtain the certification.
ISO 27001
The ISO 27001 is an Information Security Management standard that certifies that the security
requirements established by the international standardization organization have been met. The areas
of requirements are context, leadership, planning, support, operational, evaluation, and improvements.
The context requirements are to understand the organizations context, to define the expectations of
interested parties, to clarify the scope of information security management systems, and the
development of the information security management system. The second requirements that must be
met are the leadership requirements containing of the support for the information security
management system, the creation of a policy concerning security, and the assigning of responsibilities
for the information security management system. The planning requirements consist of the
formulation of actions to address information security risks and opportunities, and to formulate the
objectives and the development of plans to achieve such. Next are the support requirements. These
requirements consist of the providence of the needed ISMS resources, the encouragement and
expectation competencies, to make personnel aware of their duties, the controlling of ISMS
communications, and the managing of ISMS related information. The carrying out of the planning
and control ISMS processes, conducting information security risk assessments, and the
implementation of information security risk treatment plans are part of the operational requirements
that must be met. The requirements for the evaluation are the monitoring, measuring, and analyzation
of ISMS, the set up of internal audit programs, and the review of the organizations ISMS at set
intervals. Lastly, the improvement requirements of the identification of nonconformities and the
appropriate action taken to correct such, as well as the improvement of the ISMS must adhere to the
standards. Only if all requirements are met, the organization complies with the ISO 27001 standard
(Praxiom, 2022). c
Establishing an ISMS
Let’s look of how an organization can establish an Information Security Management System
(ISMS) in accordance with the ISO 27001 standards. The first step is to assemble an implementation
team. Once a project leader has been selected, the rest of the team will be chosen by either the project
leader or the organizations senior management. The implementation team must be well-rounded and
knowledgeable in information security. The second step would be the development of an implantation
plan. The implementation team establishes the roles and responsibilities, the rules for continuous
improvements, and raising awareness of the project internally and externally through policies. After
the completion of step two, the ISMS will be initiated. During this phase, the policy concerning the
ISMS must be established and approved by the board. The requirements and processes must be
defined, implemented, refined, and improved as well. Any model can be used as the ISO 27001 does
not specify a particular approach. The fourth step identifies the scope. Defining the scope is an
essential step in the implementation of ISMS and is crucial in identifying the scale of the ISMS. The
ISO 27001 helps to identify the security baseline with the use of a risk assessment during step five.
The sixth step is to establish a risk management process. Following the establishment of the risk
management process that identifies, analyzes, and evaluates risks according to a risk assessment, is
the implementation of a risk treatment plan. The risks treatment plan builds the security controls.
Step eight is the measurement monitoring and review of the ISMS. The monitoring and reviewing
includes reviews, audits, and analysis of the ISMS. Audits should occur annually. The final step for
the implementation is the certification in accordance with ISO 27001 standards (Irwin, 2021). c c
Benefits from Certification
Next, I would like to present a few benefits from becoming certified IAW ISO 27001. One of
the major benefits is that customers know that the organization adheres to international security
standards. The ISO 27001 is an international certification that provides credibility to the organization
internationally (Praxiom, 2022). Another great benefit is that the certification provides the
organizations management with the knowledge that their organization follows international standards.
Additionally, a certification can attract more customers. Customers want their information to be as
secure as possible.
Where to get the Certification
To become certified in accordance with the standards of ISO 27001, organizations can -
contact a certifying official/registrar to perform an audit. When all requirements are met and the
organization implemented the ISMS correctly, the registrar issues an official certificate that states that
the ISMS meets the requirements of ISO IEC 27001 2013 (Praxiom, 2022).
Summary
Let’s sum up what we have discussed during this briefing. The ISO 27001 is an international
security certification. To become certified to the ISO 27001 standards all requirements listed in their
specifications must be met. The requirements consist of context, leadership, planning, support,
operational, evaluation, and improvements. To establish ISMS in an organization, a nine-step process
should be followed to ensure compliance with the ISO 27001 standards. The main benefit of being
certified is the compliance with international standards that can be issued by a registrar.
Thank you for your undivided attention. Feel free to ask questions or leave comments. c