Security and Resilience

    Building information security

    By Redaktion techport.ai, IT-Beratung · Last updated on

    An information security management system sounds like a corporate structure with a dedicated officer and cabinets full of policies. In practice it comes down to something simple: knowing which information and systems are worth protecting, which risks exist, which measures work against them and whether they actually work.

    In the mid-market the trigger is rarely your own conviction. It is usually customers demanding evidence, or statutory duties. Both lead to the same task, and that task is worthwhile regardless of the trigger.

    How you notice it

    • A customer requests a certificate or a completed questionnaire, and the answers have to be worked out first.
    • There are security measures but no system by which they were decided.
    • Policies exist but are years old and unknown in daily work.
    • Nobody checks whether the measures introduced still work.

    Why this happens

    Security measures in the mid-market usually arise as reactions: to an incident, to a provider's recommendation, to a report in the press. Each is sensible on its own, but the common framework is missing that would show where gaps remain and where more is being done than necessary. Without that framework it is also impossible to establish whether the level of security is rising or only the number of tools.

    How we go about it

    1. Set the scope and the assets. We determine which areas, sites and processes are included and which information and systems are particularly worth protecting. A narrow, well implemented scope is worth more than a wide one on paper.
    2. Assess the risks. We record threats and weaknesses for those assets, assess them by likelihood and impact, and decide per risk whether it is reduced, transferred, avoided or knowingly accepted. That decision is made by management, not by IT.
    3. Introduce measures and policies. We implement the measures that follow from the risk assessment and write only the policies genuinely needed, in language that is understood on the shop floor.
    4. Check effectiveness and improve. We set up recurring reviews, internal and where necessary external, and make sure that incidents, review findings and changes in the company feed back into the risk assessment.

    What you gain

    • Answers to customer questionnaires in hours rather than weeks.
    • Security measures that follow from an assessment rather than from individual events.
    • A basis on which certification is possible when it is demanded.

    From our projects

    The most common mistake is too wide a scope. Including the whole company at the first attempt produces documents rather than security and loses internal support after a few months. We recommend starting with the processes that interest customers or that are covered by law, and extending afterwards. The second recurring finding: the effort for the initial certification is overestimated and the effort for maintaining it is underestimated. A certificate is valid for three years with annual surveillance, and that annual work has to be planned from the start.

    Good to know

    Several routes exist for mid-sized companies. Certification to ISO 27001 is internationally recognised and the one customers most often request. The German Federal Office for Information Security offers certification to ISO 27001 on the basis of IT-Grundschutz, which is more concrete in its requirements. For getting started there are staged approaches such as the basic protection level of IT-Grundschutz. In the automotive industry, manufacturers regularly require TISAX, an assessment and exchange mechanism based on the requirements of the German automotive industry association. Which route fits is decided less by content than by what your customers accept.

    Häufige Fragen

    Do we need our own information security officer?

    A named role yes, a dedicated post in most mid-sized companies no. What matters is that the person is independent enough to name risks even when they are inconvenient, and that they have direct access to management. In smaller companies the role is frequently filled externally and complemented by a contact person in house.

    What does a certification cost?

    The cost of the certifying body is usually the smaller part. The larger part is the internal work for building, documenting and implementing the measures, spread over six to twelve months. Solid figures are only possible once the scope has been set, because scope drives effort more than company size does.

    Let us talk about Building information security

    In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

    Further reading

    Back to the field Security and Resilience

    Sources