Certificaat ISO27001

Certificate for ISO 27001

First the golden rules then the software ....

From Metaware's knowledge center .
Keywords:
Certification, information security certification, certification ISO27001 2022, ISO 27001 software, successful, information security, management system, ISMS, Information Security Management System, online management system, web-based management system, multi-site system

Please note that ISO 27001 has changed - ISO 27001:2022. Our colleagues at Meta-audit.nl are happy to explain:
ISO 27001:2022 vs ISO 27001:2013
ISO 27001:2022 step-by-step plan

Preparation for information security certification

The crux is in good preparation. Certification of your management system is the final step in this project. Start by optimizing the process around first, then the software. Don't worry about web-based or online management systems (yet). Multi-site or not. For a successful certification process , remember the 10 golden rules:

 

  1. Define what you want: policy and objective
    Provide clarity in what you want with the information security process and how to manage it. Charities are
    SMART (Specific, Measurable, Achievable, Realistic, Time-bound).
     
  2. Where are you now?
    Determine where you stand as an organization with regard to information security management. At what level are you with your ISMS, management system? Where do you want to go and then get to work on all facets of the management system (ISMS - Information Security Management System) that deviate or are missing. Only then start improving existing (management) processes.
    For example, look at the list of mandatory documents from our fellow specialists at Meta-audit.nl

     
  3. Leadership 
    Which is also the subject of a chapter in the ISO 9001:2015 standard ! Let management show leadership, its own policy (for information security and possibly quality, safety, ..) and set a good example.

     
  4. It's all about support
    Support within the organization, that's what it's all about. Motivate the employees and explain why process control is necessary and how it should be done. If everyone cooperates on 'information security', steps can be taken.

     
  5. KISS: Keep It Simple and Stupid
    Avoid dusty thick information security manuals with long procedures, protocols, and instructions that no one is going to read. Create an accessible ISMS tailored to the risks present. Think of KISS.
     
  6. Make it your own management system
    Forget old, dusty manuals and standard operating procedures. No copies of consultants. Make sure the documents are representative of your own working method. 

     
  7. Delegate to the business
    The ISMS is not the security officer's party. Delegate the use and maintenance of the ISMS to the business. That's where it happens.

     
  8. Check and improve.
    Monitor and manage the progress in the improvement process. Think of the plan-do-check-act cycle.


    Plan:    Plan an improvement
    Do:    Perform an improvement
    Check:    Analyze the results
    Act:    Implement and secure the new way of working

     
  9. Expertise
    Provide the right expertise in information security processes. If you don't have it yourself, buy it. An investment that pays off.

     
  10. A management management system is a means, not an end.
    Use the management system as a lever to keep the organization effective and to further professionalize it. It is more than a certificate ISO27001:2013 on the wall. Also think of the possibilities of modern online or web-based management systems.


Following the rules the software.

This short video shows the use of the online web-based management system Proware, a cloud solution. Very suitable for multi-site application. 
For a detailed explanation, check out our Proware product page, the Proware demo environment or try it NOW (in 60 seconds ..).
And then immediately apply the golden rules ...