• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register | Login to Member's Area

 
 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • NDL Seminar: Take the office with you - easily
    8th February
    London, United Kingdom
  • NDL Seminar: Take the office with you - easily
    9th February
    Greater Manchester, United Kingdom
POPULAR PAPERS
  • Best practices for cloud security by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Observations - "Old men are fond of giving advice to console themselves for being no longer in a position to give bad examples." - Francois de la Rouchefoucald

PAGE TOOLS
  • Request Reprints
  • Tell A Friend
  • Contact Author
RECENT POSTS
  • Secure disposal of old IT equipment
  • A critical software problem for banks
  • Auditors want to know about individuals, not groups
  • IT security vendors can't all be right, but they can all be wrong
  • Don't forget the network
  • Consumers say no [to data leaks]
ADVERTISEMENT
fotoSENSE - Click here!
BLOG ARCHIVE
  • December, 2011
  • November, 2011
  • October, 2011
  • September, 2011
  • August, 2011
  • July, 2011
  • April, 2011
  • February, 2011
  • January, 2011
  • November, 2010
  • October, 2010
  • September, 2010
Voipfone VoIP 30 Day FREE Trial Click To Sign Up Now
Blogs > Quocirca

The right question to ask about the ISO27001 IT security standard

Bob Tarzey By: Bob Tarzey, Service Director, Quocirca
Published: 1st December 2009
Copyright Quocirca © 2009
Logo for Quocirca

Standards exist to provide reassurance when buying products and services. For example the Kitemark standard, owned awarded by the British Standards Institute (BSI), provides reassurance about the quality and safety of a wide range of products and services.

Attaining a Kitemark often requires that another more specific standard has already been reached. If you crash your car and take it to a repair shop displaying the Kitemark logo, the service provider is required to have achieved the technical specification PAS-125 (another BSI standard). On the BSI web site, it says that "repairers will be able to secure their future business by being able to independently prove to insurers and the motorist that their vehicle body repair service meets all the required safety criteria of PAS 125 and the Kitemark scheme".

The "all" is emphasised here because not all standards require that all their criteria are met. The ISO27001 IT security standard (specified by the American National Standards Institute—ANSI) provides reassurance about the security controls in place for IT deployments. In Quocirca's freely available report, Managed Hosting in Europe, published in June 2009 and sponsored by NTT Europe Online, the status of ISO27001 compliance was listed as a measure of the reassurance around the security of services on offer. For some vendors it was reported as being "in progress".

It may surprise some that "in progress" is a valid status for any organisation claiming it is ISO27001 compliant. The standard itself provides guidelines on deploying an Information Security Management System, or ISMS, and states in section 1.1 (April 2006 publication) that the ISMS is designed to ensure the selection of adequate and proportionate security controls that protect information assets and give confidence to interested parties. In short, the security controls specified in ISO27001 are optional, dependent on the needs of the supplier and its customers.

Quocirca is not suggesting any shortfall in those controls but merely reminding buyers of ISO27001 compliant services of the precise question they must ask. It is not "is your service ISO27001 compliant?", but "have you adopted ISO27001 and, if yes, which controls have you adopted and which ones have you not?"

This is the likely explanation for the finding in a recent survey into privileged users, carried out by Quocirca and sponsored by CA, that many organisations which claim ISO27001 compliance do not carry out the good practices with regards to privileged user management that are described in the standard.

Interestingly, the BSI also offers advice on its web site with regard to ISO27001; here it says "once the assessment has been successfully completed, we'll issue a certificate of registration, clearly explaining the scope of your certification"—no sign of the word "all" there, and buyers should assess vendors the scope accordingly.

Reader Comments

The messages above were all contributed by IT-Director.com readers. Whilst we take care to remove any posts deemed inappropriate, we can take no responsibility for these comments. If you would like a comment removed please contact our editorial team.

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

Voipfone VoIP 30 Day FREE Trial Click To Sign Up Now


  • Feedback
  • | Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd. | Tel: 01908 880760