SlideShare a Scribd company logo
ISO27001:2005 Implementation: Benefits and Challenges

   22 November 2011                Han van Thoor
Subjects discussed:

Challenges
Managing management and peers
Risk Assessment
Statement of Applicability
Post certification


Benefits
Challenges


                      Manage managers

Commitment : Is the implementation done because we have to due to our
  customers/legal reasons or is there a real security awareness within
                           management ?

Finance : Is there a real budget, is there a provision for unforseen costs ?


             Implementation times: how long do you have ?
Challenges


                          Manage peers

      Buy-in : Translate security policies into accepted work practices

Managing change : People might have to change behaviour and procedures
Challenges


Risk Assessment

 Know your assets!

   Methodology
Challenges


  Risk Assessment Methodology

   What are your Key Business Processes (KBP)
What information assets are being used by the KPB's
            How valuable are the assets
 Score risks against assets to identify highest risks
Challenges


 Example of a methodology




(Integrity+Confidentiality+Availability)*(Likelihood)*(Value)
Challenges


Statement of applicability

     The less the better ?
Challenges


Post- certification

  Maturing the ISMS
SME versus Corporate



            Implementation   Cost       Complexity
            Time

SME         < 6 months       € 0 - ??   Simple, few systems,
                                        people, direct lines

Corporate   < 18 months      € 0 - ??   More complex, more
                                        systems,more people
                                        longer decision times
Benefits
       Proof of security to third parties (for clients, partners and legal purposes)

     Competitive advantage: ‘documented quality’ by an independent authority

            Cost reductions through transparent, optimised structures.

             Security becomes an integral part of business processes

           Knowledge and monitoring of the IT risks and residual IT risks

                    Documentation of structures and processes

                    Increased employee awareness of security

      Evaluation of the organisation’s processes from a security point of view.

Prioritising the security of the business operations: business continuity management

                           Globally recognised standard

                     Potential reduction in insurance premiums

      Referencing the IT process management standard (ITIL) to ISO 27001

    Seamless transition from ISO 27001 in management systems to ISO 9000

More Related Content

PPT
ISO 27001 Benefits
PPTX
27001 awareness Training
PDF
Isms awareness presentation
PDF
What is ISO 27001 ISMS
PPTX
Basic introduction to iso27001
PPTX
ISO 27001 - Information security user awareness training presentation - part 3
PDF
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
PDF
ISO27001: Implementation & Certification Process Overview
ISO 27001 Benefits
27001 awareness Training
Isms awareness presentation
What is ISO 27001 ISMS
Basic introduction to iso27001
ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001_2022 What has changed 2.0 for ISACA.pdf
ISO27001: Implementation & Certification Process Overview

What's hot (20)

PDF
2022 Webinar - ISO 27001 Certification.pdf
PPTX
Iso iec 27001 foundation training course by interprom
PPTX
What is iso 27001 isms
PPTX
Presentation on iso 27001-2013, Internal Auditing and BCM
PDF
A to Z of Information Security Management
PPTX
ISO_ 27001:2022 Controls & Clauses.pptx
PPTX
ISO 27001 Awareness/TRansition.pptx
PDF
Why ISO27001 For My Organisation
PDF
ISO 27005:2022 Overview 221028.pdf
PPTX
Iso 27001 awareness
DOCX
Iso 27001 2013 Standard Requirements
PPT
ISO 27001 - Information Security Management System
PPS
ISO 27001 2013 isms final overview
PDF
ISO 27001:2022 What has changed.pdf
PDF
ISO/IEC 27001:2013 An Overview
PDF
ISO 27001 2002 Update Webinar.pdf
PPTX
ISO 27001 - information security user awareness training presentation - Part 1
PDF
Information security management system (isms) overview
PDF
2022 Webinar - ISO 27001 Certification.pdf
Iso iec 27001 foundation training course by interprom
What is iso 27001 isms
Presentation on iso 27001-2013, Internal Auditing and BCM
A to Z of Information Security Management
ISO_ 27001:2022 Controls & Clauses.pptx
ISO 27001 Awareness/TRansition.pptx
Why ISO27001 For My Organisation
ISO 27005:2022 Overview 221028.pdf
Iso 27001 awareness
Iso 27001 2013 Standard Requirements
ISO 27001 - Information Security Management System
ISO 27001 2013 isms final overview
ISO 27001:2022 What has changed.pdf
ISO/IEC 27001:2013 An Overview
ISO 27001 2002 Update Webinar.pdf
ISO 27001 - information security user awareness training presentation - Part 1
Information security management system (isms) overview
Ad

Viewers also liked (9)

PDF
Managing Contract Obligations and Milestones with SharePoint
PPTX
Itil,cobit and ıso27001
PDF
ISO 27001
PPTX
Types of Information Resources
PPTX
Ims (integrated Management system )
PPT
Working with students and ISO27001
PPT
Information Resources Management
PDF
ISO 27001 Implementation_Documentation_Mandatory_List
PPTX
Iso 27001 isms presentation
Managing Contract Obligations and Milestones with SharePoint
Itil,cobit and ıso27001
ISO 27001
Types of Information Resources
Ims (integrated Management system )
Working with students and ISO27001
Information Resources Management
ISO 27001 Implementation_Documentation_Mandatory_List
Iso 27001 isms presentation
Ad

Similar to ISO 27001 Certification - The Benefits and Challenges (20)

PDF
Unlocking the Benefits of ISO 27001 Certification for Information Security.pdf
PPT
ISO 27001 Certification-The Gold Standard for Information Security-IAS-GULF-UAE
PPT
ISO 27001 Certification-The Gold Standard for Information Security
PPT
The Business Of Identity, Access And Security V1.0
PDF
Riskpro Information Risk Management
PPT
4 System For Information Security
PPT
Identity Management: Risk Across The Enterprise
PDF
Riskpro information risk management
PDF
Riskpro Information Risk Management
PDF
Riskpro Information Risk Management
PPTX
Unlocking the Benefits of ISO 27001 Certification for Information Security.pptx
PDF
G12: Implementation to Business Value
PPTX
iso-27001-compliance-framework-cybersecurity-india-defenderrabbit-2025.pptx
PDF
CQI-IRCA 27001:2013 Lead Auditor Course
PDF
A Comprehensive Guide To Information Security Excellence ISO 27001 Certificat...
PDF
CV jagroop jagpal
PPT
ClockworkISMS
PDF
Bpo risk management
PDF
I N F O R M A T I O N & C Y B E R S E C U R I T Y A U D I T S
PDF
ISO 27001 Certification What You Need to Know to Get Started.pdf
Unlocking the Benefits of ISO 27001 Certification for Information Security.pdf
ISO 27001 Certification-The Gold Standard for Information Security-IAS-GULF-UAE
ISO 27001 Certification-The Gold Standard for Information Security
The Business Of Identity, Access And Security V1.0
Riskpro Information Risk Management
4 System For Information Security
Identity Management: Risk Across The Enterprise
Riskpro information risk management
Riskpro Information Risk Management
Riskpro Information Risk Management
Unlocking the Benefits of ISO 27001 Certification for Information Security.pptx
G12: Implementation to Business Value
iso-27001-compliance-framework-cybersecurity-india-defenderrabbit-2025.pptx
CQI-IRCA 27001:2013 Lead Auditor Course
A Comprehensive Guide To Information Security Excellence ISO 27001 Certificat...
CV jagroop jagpal
ClockworkISMS
Bpo risk management
I N F O R M A T I O N & C Y B E R S E C U R I T Y A U D I T S
ISO 27001 Certification What You Need to Know to Get Started.pdf

Recently uploaded (20)

PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
cuic standard and advanced reporting.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Encapsulation theory and applications.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Machine learning based COVID-19 study performance prediction
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
A Presentation on Artificial Intelligence
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Electronic commerce courselecture one. Pdf
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Cloud computing and distributed systems.
PDF
Review of recent advances in non-invasive hemoglobin estimation
Reach Out and Touch Someone: Haptics and Empathic Computing
cuic standard and advanced reporting.pdf
Empathic Computing: Creating Shared Understanding
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Encapsulation theory and applications.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Spectral efficient network and resource selection model in 5G networks
Machine learning based COVID-19 study performance prediction
The Rise and Fall of 3GPP – Time for a Sabbatical?
A Presentation on Artificial Intelligence
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Electronic commerce courselecture one. Pdf
MYSQL Presentation for SQL database connectivity
Cloud computing and distributed systems.
Review of recent advances in non-invasive hemoglobin estimation

ISO 27001 Certification - The Benefits and Challenges

  • 1. ISO27001:2005 Implementation: Benefits and Challenges 22 November 2011 Han van Thoor
  • 2. Subjects discussed: Challenges Managing management and peers Risk Assessment Statement of Applicability Post certification Benefits
  • 3. Challenges Manage managers Commitment : Is the implementation done because we have to due to our customers/legal reasons or is there a real security awareness within management ? Finance : Is there a real budget, is there a provision for unforseen costs ? Implementation times: how long do you have ?
  • 4. Challenges Manage peers Buy-in : Translate security policies into accepted work practices Managing change : People might have to change behaviour and procedures
  • 5. Challenges Risk Assessment Know your assets! Methodology
  • 6. Challenges Risk Assessment Methodology What are your Key Business Processes (KBP) What information assets are being used by the KPB's How valuable are the assets Score risks against assets to identify highest risks
  • 7. Challenges Example of a methodology (Integrity+Confidentiality+Availability)*(Likelihood)*(Value)
  • 9. Challenges Post- certification Maturing the ISMS
  • 10. SME versus Corporate Implementation Cost Complexity Time SME < 6 months € 0 - ?? Simple, few systems, people, direct lines Corporate < 18 months € 0 - ?? More complex, more systems,more people longer decision times
  • 11. Benefits Proof of security to third parties (for clients, partners and legal purposes) Competitive advantage: ‘documented quality’ by an independent authority Cost reductions through transparent, optimised structures. Security becomes an integral part of business processes Knowledge and monitoring of the IT risks and residual IT risks Documentation of structures and processes Increased employee awareness of security Evaluation of the organisation’s processes from a security point of view. Prioritising the security of the business operations: business continuity management Globally recognised standard Potential reduction in insurance premiums Referencing the IT process management standard (ITIL) to ISO 27001 Seamless transition from ISO 27001 in management systems to ISO 9000