Certificate for ISO 27001
First the golden rules then the software ....
From Metaware's knowledge center .
Keywords: Certification, information security certification, certification ISO27001 2022, ISO 27001 software, successful, information security, management system, ISMS, Information Security Management System, online management system, web-based management system, multi-site system
Please note that ISO 27001 has changed - ISO 27001:2022. Our colleagues at Meta-audit.nl are happy to explain:
- ISO 27001:2022 vs ISO 27001:2013
- ISO 27001:2022 step-by-step plan
Preparation for information security certification
The crux is in good preparation. Certification of your management system is the final step in this project. Start by optimizing the process around first, then the software. Don't worry about web-based or online management systems (yet). Multi-site or not. For a successful certification process , remember the 10 golden rules:
- Define what you want: policy and objective
Provide clarity in what you want with the information security process and how to manage it. Charities are SMART (Specific, Measurable, Achievable, Realistic, Time-bound).
- Where are you now?
Determine where you stand as an organization with regard to information security management. At what level are you with your ISMS, management system? Where do you want to go and then get to work on all facets of the management system (ISMS - Information Security Management System) that deviate or are missing. Only then start improving existing (management) processes.
For example, look at the list of mandatory documents from our fellow specialists at Meta-audit.nl
- Leadership
Which is also the subject of a chapter in the ISO 9001:2015 standard ! Let management show leadership, its own policy (for information security and possibly quality, safety, ..) and set a good example.
- It's all about support
Support within the organization, that's what it's all about. Motivate the employees and explain why process control is necessary and how it should be done. If everyone cooperates on 'information security', steps can be taken.
- KISS: Keep It Simple and Stupid
Avoid dusty thick information security manuals with long procedures, protocols, and instructions that no one is going to read. Create an accessible ISMS tailored to the risks present. Think of KISS.
- Make it your own management system
Forget old, dusty manuals and standard operating procedures. No copies of consultants. Make sure the documents are representative of your own working method.
- Delegate to the business
The ISMS is not the security officer's party. Delegate the use and maintenance of the ISMS to the business. That's where it happens.
- Check and improve.
Monitor and manage the progress in the improvement process. Think of the plan-do-check-act cycle.
Plan: Plan an improvement
Do: Perform an improvement
Check: Analyze the results
Act: Implement and secure the new way of working
- Expertise
Provide the right expertise in information security processes. If you don't have it yourself, buy it. An investment that pays off.
- A management management system is a means, not an end.
Use the management system as a lever to keep the organization effective and to further professionalize it. It is more than a certificate ISO27001:2013 on the wall. Also think of the possibilities of modern online or web-based management systems.
Following the rules the software.
This short video shows the use of the online web-based management system Proware, a cloud solution. Very suitable for multi-site application.
For a detailed explanation, check out our Proware product page, the Proware demo environment or try it NOW (in 60 seconds ..).
And then immediately apply the golden rules ...