Featured

ISO 27001 Standard: Increase controls to reduce risks

Let's now see what controls are required by ISO 27001. These are practices to be implemented to reduce risks to acceptable levels. Controls can be technical, organizational, legal, physical, human, etc.

Annex A of ISO 27001 lists 114 controls organized in 14 sections numbered from A.5 to A.18.

Technical controls are mainly implemented in information systems, using software, hardware and firmware components added to the system such as, for example, backups, antivirus software, etc. Organizational controls are implemented by defining the rules to be followed and the expected behavior for users, equipment, software and systems. Legal controls are implemented by ensuring that the rules and expected behaviors follow and enforce laws, regulations, contracts and other similar legal instruments to which the organization must comply (e.g. non-disclosure agreements or those relating to the level of service).

Physical controls are mainly implemented using equipment or devices that have a physical interaction with people and objects (e.g. CCTV cameras, alarm systems, locks, etc.) Human resource controls are implemented by providing knowledge, education, skills or experience to people to enable them to perform activities safely (e.g. awareness training on security regulations, training for ISO 27001 internal auditors, etc.)

Coming to the documents that are mandatory for certificarsi secondo la ISO 27001, we have a minimum set of policies, procedures, plans, records and other necessary documented information.

Specifically, the standard requires the drafting of the following documents:

  • Scope of the system (point 4.3)
  • Policy and objectives for information security (points 5.2 and 6.2)
  • Risk assessment and treatment methodology (point 6.1.2)
  • Statement of Applicability (point 6.1.3 d)
  • Risk treatment plan (points 6.1.3 e and 6.2)
  • Risk assessment report (point 8.2)
  • Definition of security roles and responsibilities (controls A.7.1.2 and A.13.2.4)
  • Inventory of assets (control A.8.1.1)
  • Acceptable use of assets (control A.8.1.3)
  • Access control policy (control A.9.1.1)
  • Operating procedures for IT management (control A.12.1.1)
  • Engineering principles for a secure system (control A.14.2.5)
  • Supplier security policy (control A.15.1.1)
  • Problem management procedure (control A.16.1.5)
  • Business continuity procedures (control A.17.1.2)
  • Legal, regulatory and contractual requirements (control A.18.1.1)

And these are the mandatory recordings:

  • Records of training, skills, experience and qualifications (point 7.2)
  • Monitoring and measurement results (point 9.1)
  • Internal audit program (point 9.2)
  • Results of internal audits (point 9.2) 
  • Results of the management review (point 9.3) 
  • Results of corrective actions (point 10.1)
  • Records of user activity, exceptions and security-related events (controls A.12.4.1 and A.12.4.3)

Of course, if it deems it necessary, a company can decide to draw up additional documents.

Once all the material has been prepared, an organization can richiedere la certificazione ISO 27001 by inviting an accredited certification body to carry out the certification audit and, if the audit is successful, to issue the company with the certificate that will prove that the company is fully compliant with the standard.

Alla famiglia della ISO 27000 also belong other standards, since ISO 27000 mainly defines what is necessary to certify but does not specify how to do it. These further indications are given by the other documents for information security.

Specifically, there are more than 40 standards in the family but the most commonly used are:

UNI CEI EN ISO/IEC 27000 “Information technology – Security techniques – Management systems for information security _ Overview and vocabulary” which provides terms and definitions used in the series of standards

UNI CEI EN ISO/IEC 27002 “Information

Contacts

Registered Office:
Via Nazario Sauro, 4 – 20059 Vimercate (MI)
Milan Office:
Via della Resistenza, 113 - 20090 Buccinasco
La Spezia Office:
Via Paolo Emilio Taviani, 52 – 19125 La Spezia (SP)
Sitemap