ISO 27001/BS 25999 documents, presentation decks and implementation guidelines


Free_Downloads
 
Newsletter
 
Sign up to our free Newsletter and as bonus you'll receive my tips on how to launch an information security and business continuity project.
 
 
 
 
 
 
    

UPCOMING WEBINARS

    

 
ISO 27001 & BS 25999-2: Why is it better to implement them together?

    

Wednesday
May 23, 2012

    Register_now_green
    

 
Risk Management Part 1: Risk assessment methodology and risk assessment process

Monday
May 21, 2012

    Register_now_green
 
 
 
 

5 greatest myths about ISO 27001

'By 'Dejan Kosutic on January 24, 2011

Very often I hear things about ISO 27001 and I don’t know whether to laugh or cry over them. Actually it is funny how people tend to make decisions about something they know very little about – here are the most common misconceptions:

The standard requires…”

“The standard requires passwords to be changed every 3 months.” “The standard requires that multiple suppliers must exist.” “The standard requires the disaster recovery site to be at least 50 km distant from the main site.” Really? The standard doesn’t say anything like that. Unfortunately, this kind of false information I hear rather often – people usually mistake best practice for requirements of the standard, but the problem is that not all security rules are applicable to all types of organizations. And the people who claim this is prescribed by the standard have probably never read the standard.

We’ll let the IT department handle it”

This is the management’s favorite – “Information security is all about IT, isn’t it?” Well, not really – the most important aspects of information security include not only IT measures, but also organizational issues and human resource management, which are usually out of reach of IT department. See also Information security or IT security.

We’ll implement it in a few months”

You could implement your ISO 27001 in 2 or 3 months, but it won’t work – you would only get a bunch of policies and procedures no one cares about. Implementation of information security means you have to implement changes, and it takes time for changes to take place.

Not to mention that you must implement only those security controls that are really needed, and the analysis of what is really needed takes time – it is called risk assessment and risk treatment.

This standard is all about documentation”

Documentation is an important part of ISO 27001 implementation, but the documentation is not an end in itself. The main point is that you perform your activities in a secure way, and the documentation is here to help you do it. Also, the records you produce will help you measure whether you achieve your information security goals and enable you to correct those activities that underperform.

The only benefit of the standard is for marketing purposes”

“We are doing this only to get the certificate, aren’t we?” Well, this is (unfortunately) the way 80 percent of the companies think. I’m not trying to argue here that ISO 27001 shouldn’t be used in promotional and sales purposes, but you can also achieve other very important benefits – like preventing the case of WikiLeaks happening to you. See also Four key benefits of ISO 27001 implementation and Lessons learned from WikiLeaks: What is exactly information security?

The point here is – read ISO 27001 first before you form your opinion about it; or, if it’s too boring for you to read it (which I admit it is), consult with someone who has some real knowledge about it. And try to get some other benefits, other than marketing. In other words, increase your chances to make a profitable investment in information security.

You can also check out our series of ISO 27001 video tutorials which explain every step in ISO 27001 implementation (commercially sold videos).

0saves
If you enjoyed this post, please consider leaving a comment in a box below or subscribing to the RSS feed to have future articles delivered to your feed reader.

This post is also available in: German, Japanese, Spanish, Croatian, Portuguese (Brazil)


  • Gary Evans

    One mistake I’ve noted over the yers is that contracts require 27002 compliance or certification instead of 27001 compliance or certification.

    It often falls on def ears when I say “we can’t comply with 27002, only 27001.”. Do they expect all controls in 27002 to be implemented? They forget (or ignore) the requirement for a risk assessment, choosing risk treatment and then getting management to choose the treatments.

  • Dejan Kosutic

    I agree with you completely – these are probably myths #6 and #7 – confusing ISO 27001 with ISO 27002, and not understanding the importance of selecting the appropriate controls.

  • Gerald F.

    It’s the same challenge with ANY IT related standard & regulation! Everyone is bitching around, like it’s all about ‘producing papers’ & ‘checklist-audits’, but all these comments are just related to misconsumptions and picking up some comments in the wonderful world of ‘information security overflow’! Just think about PCI, how much rumors exist about there uselessness – even in the so called security expert community – how wrong they are (why do we have still so many traditional breaches – complete lack of payment security architectures!). On the other hand, there are really a few serious resources out there, understanding & also providing a practicable approach of INFORMATION SECURITY to companies!