By Richard Nealon
I’ve always been a fan of 27001, even before it was born. Back in the early 1990s there were only two publicly available computer security standards – BS7799 (which had been born out of an initiative from BT, Midland Bank, Unilever, Shell BP and a bunch of other UK corporates), and the BSI IT Baseline Protection Manual (published by the German government standards office). I gravitated towards the former and watched it become adopted into ISO as 17799 in 2000, and subsequently into 27001 in the mid 2000’s.
Back then, the focus for many organisations was “self-compliance” or “alignment” because there was really no business case for most companies in being “certified”. These two standards were the only benchmarks for companies to aspire to, and assess themselves against. We followed good practice in writing our internal security standards to be closely aligned with the BS/ISO standard so that we could convince management, auditors, and regulators/supervisors that we understood security, took it seriously, and we were broadly aligned with our peers.
That all changed in the last ten years. All companies in the supply chain from banks down to manufacturers of widgets are being actively pressurised by their regulators, supervisors, suppliers, partners, clients, to be independently certified to ISO27001.
After Quality Assurance, Environmental Management, and Health & Safety, Information Security Management Systems (ISMS) (1) is the ISO next most popular standard. The number of globally certified entities has risen from about 23k in 2014 to nearly 59k in 2021, mainly driven by external pressure from clients and regulators.
For regulated organisations, service suppliers, or those in the public eye, I’d highly recommend that you think about the business opportunities that ISO 27001 certification can open up to you at minimal cost and effort. Trust is the new gold, and ISO 27001 builds trust.
Is your organisation looking to achieve ISO 27001 certification and unlock its numerous benefits?
From gap assessment, to implementation and ongoing ISMS management , we guide organisations through the certification process, ensuring a smooth and successful journey towards information security excellence. Our experienced & certified consultants possess in-depth knowledge of ISO 27001 standards and information security management systems. We offer comprehensive assistance tailored to your unique organisational needs. By going beyond documentation we help you to integrate information security practices into your processes and workflows, fostering a culture of security.
Contact us today to embark on your ISO 27001 certification journey and fortify your data security.
ISO 27001:2022 certification helps to improve data security and trust. Its benefits encompass enhanced security, regulatory compliance, improved resilience, competitive advantage, and streamlined efficiency. With our professional assistance, organisations can effectively navigate the certification path, achieving information security excellence.
Richard Nealon is an official certified instructor for ISC2 and a seasoned Information Security and Risk Management professional with over 35 years’ experience.In his role as a vCISO with clients across a range of industries, Richard has worked with clients to enable them to manage their cyber risk. In addition to vCISO services, Cycubix offers cybersecurity consultancy services tailored to help clients secure the applications critical to their business.