Free Newsletters

   All InfoWorld Newsletters
Security Watch | Matt Hines » Is ISO 27001 the new ISO 9001?

May 15, 2006 | Comments: (0)

Is ISO 27001 the new ISO 9001?

I've just heard that the Federal Reserve Bank of New York has become the first organization in North America to be certified to the new ISO 27001 global standard for information security best practices.

I'm wondering whether this Fed's certification will cause others to join in on this information security benchmark - hopefully it will.

While I believe standardization is usually good, especially when it comes to information security, it can cause bottlenecks as the process takes place. I remember being part of a large ISO 9000 certification process pre-2000, and of course now all I can remember is having to memorize the company's mission statement in case I was ever asked. But overall these certifications are a good thing, as they offer consistency and organization when it comes to documentation, training, change/process management and operational procedures within an enterprise.

The ISO 27001:2005 standard, that replaced BS7799-2:2002 (which already had over 2,500 organizations worldwide certified against it), is titled "Information Security Management - Specification With Guidance for Use" and is supposed to follow along the lines of ISO 9001 and ISO 14001 for management homogeneity. Being certified for ISO 27001 should also grease the process for other compliance requirements, including the Gramm-Leach-Bliley Act (GLBA), the Health Insurance Portability and Accountability Act (HIPAA) and the Sarbanes-Oxley Act (SOX).

About ISO/IEC 27001:2005

ISO 27001 is the formal standard against which organizations may seek independent certification of their Information Security Management Systems, meaning their framework to design, implement, manage, maintain and enforce information security processes and controls systematically and consistently throughout the organizations. The final version of ISO 27001:2005 is available now from ISO or BSI. More information is available at www.iso.org, www.bsiamericas.com and www.xisec.com.

Posted by Victor R. Garza on May 15, 2006 12:47 PM


RATE THIS ARTICLE:





 

  •  
  • COMMENTS




Actually, there are several other registrations that are in place. We completed ours in December of 2005, about 24 hours behind Fujitsu Japan, who lay claim to being the first organization worldwide to be 27001 certified.

I certainly hope that people realize the potential of utilizing an ISMS based on ISO/IEC 17799 and ISO/IEC 27001. The benefits are numerous, including for non-IT areas.

I would also advise people to watch what industry players are doing, to see what is coming down the pipe. The Federal Reserve Bank of New York was originally certified under BS 7799, and the entire Federal Reserve system is slowing appearing to move this direction. This can have a major impact on how organizations deal with Safety and Soundness reviews.

Scott

Posted by: Scott Erkonen at May 24, 2006 07:33 AM

Victor,

Indeed I do believe that the uptake of ISO 27001 will be similar to that of ISO 9001 in time. We are in the midst of seeing greater regulatory and statutory controls to govern security & privacy and ISO presents a measurable and certifiable framework to address such issues; and much more.

As the breach of information security assets & intellectual property becomes more and more frequent, and it will (poor VA), organizations will look to ensure that the data they are trading with business partners, vendors and employees is done so securely. Such that they know what the risks to these transactions are and have addressed those risks from a defensible position: enter ISO. I imagine the legislative landscape of the future won't take too kindly to those entities that are incapable of and/or disinterested in securing their assets. There's simply too much at stake.

Posted by: Greg Porter at May 24, 2006 08:28 AM

Scott;

Congratulations on your 27001 certification. For the record, the Federal Reserve Bank of NY currently holds two certifications. The 27001:2005 certification of the NIRT Security Operations Center and BS7799-2:2002 for their ISF organization. I could not agree more with your comment regarding the benefits of certification.

Barry

Posted by: Barry Kouns at May 31, 2006 12:46 PM

Scott;

Congratulations on your 27001 certification. For the record, the Federal Reserve Bank of NY currently holds two certifications. The 27001:2005 certification of the NIRT Security Operations Center and BS7799-2:2002 for their ISF organization. I could not agree more with your comment regarding the benefits of certification.

Barry

Posted by: Barry Kouns at May 31, 2006 12:47 PM

As a security consultant I have specialized in the networking aspects of Security. Management of security is an important aspect that companies should master. With ISO 27001 it is the opportunity for companies to highly improve their security and build people awarness as well as processes.

Congratulation for your certification

Christian ALT

Telecom and Logistics Associates
Certified auditor ISO 27001

Posted by: Christian ALT at June 15, 2006 05:14 AM

My first ISO 27001:2005 audit is in one week, and I can say without a doubt it has been extremely useful. We have found many areas where we needed improvement, and created processes to resolve those issues. We now have documentation for almost all of the processes we do, assuring uniform results no matter who performs a task. Other groups within my organization have been ISO 27001 certified with the same auditor that is coming to perform my group's audit, and they all have stated that he is very thorough, adding to the credibility of the certification.

Posted by: Aaron at January 12, 2007 07:48 AM

Hi Scott,

Congratulations on your certification, I know I am too late to congratulate you, but just wanted to add a point here that most of the organizations even today ignore the importance of security issues and it is once they face any threat they realise that they have to go for ISO 27001. It is all basically depends on the top management if they really want to be secure in this fast growing technology world.

Regards
Kumar M
Process Consultant(ISO 9001, ISO 27001,CMMI)
kumar.exe@gmail.com

Posted by: Kumar at April 19, 2007 05:43 AM

Technology White Papers

 

InfoWorld Technology Marketplace

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
» BUY A LINK NOW

Sponsored Technology Links