In the age of digitization, it is valuable information that must be preserved or protected above all. For companies, this means that alongside data protection, information security is an absolute must. The good news is: companies that have a certified quality management system in accordance with ISO 9001 have already created a good basis for the step-by-step introduction of fully comprehensive information security.

Information Security meets Quality Management

The topic of information security is not new. The dangers threatening the extensive information landscape in organizations have long been known. According to the April 2019 German BSI "Cyber Security Survey," 43% of large companies reported being affected by cyber security incidents in 2018.

For small and medium-sized enterprises, the figure was 26%. And according to the "Situation Report on IT Security in Germany 2021" from the German Federal Office for Information Security (BSI), cases of cybercrime have once again increased significantly. In the reporting period from June 1, 2020, to May 31, 2021, not only was there an increase of a good 22 percent in new malware variants (around 144 million), but the quality of the attacks also continued to rise considerably. In the process, many perpetrators exploited the Corona distress of many companies and people.

However, the security of confidential company information is still neglected. There is often a lack of caution and forethought when processing and storing information. Awareness of the consequences of data theft and its like is also far from sufficiently developed everywhere. In some places, companies are also reluctant to invest the time and effort required to effectively protect their sensitive information.

 

Step by step towards greater information security

But the effort required for data security doesn't have to be that great. The good news is that many companies do not have to implement a comprehensive information security management system in one fell swoop. For critical infrastructures (CRITIS), on the other hand, this is required by the German IT Security Act.

A step-by-step approach is also conceivable. This means that the first step, at least in companies that have a quality management (QM) system in accordance with ISO 9001, can be an update of the required risk-based approach - but already with a view to the corresponding requirements of the important information security standard ISO 27001.

Loading...
Free White Paper

ISO 9001 and ISO 27001 in the era of digitalization

The use of modern communication tools introduces entirely new considerations for managing documented information: availability, integrity, and confidentiality. An intriguing topic? Now available as a free white paper!

Content:

  • Proper Handling of Documented Information
  • Effectively Protecting Documented Information
  • ISO 27001: The Foundation for Secure Digitization

Information security and quality management

ISO 27001 vs. ISO 9001: Where are the connections? First, it must be noted that the ISO 9001 quality management standard does require a risk-based approach across the board. However, the implementation of this management system requirement is largely up to your organization. For example, quality management does not require a separate process for risk assessment, but this is unquestionably too little with regard to information security. Nevertheless:

The risk assessment for quality management issues can easily be extended to the topic of information security.

To do this, it is helpful to look at the requirements for identifying and dealing with security risks of ISO 27001 for an information security management system (ISMS). Most aspects can be implemented by users of a quality management system with reasonable effort - as a first step on the way to holistic information security, mind you. 

 

Information security - risks and opportunities

Both international standards, ISO 27001 for information security and ISO 9001 for quality management, deal with the relevant topics in Chapter 6.1 "Measures for dealing with risks and opportunities". In essence, the aim is to ensure three essential aspects in the management system:

  • Achieving your organization's intended results
  • Preventing or reducing undesirable effects 
  • Achieving continuous improvement through compliance with certain standards

 

With respect to information security, these are primarily the three essential protection goals:

  • Loss of confidentiality
  • Integrity of information
  • Availability of information

 

The ISMS standard ISO 27001 specifies the following requirements (section 6.1.1):

  • Determining risks and opportunities
  • Planning measures to deal with the identified risks and opportunities
  • Plan how the measures will be integrated into the company processes and implemented  

 

Identifying and dealing with risks

The next subchapter (6.1.2) of ISO 27001 requires the establishment and application of an information security risk assessment process. This process must establish and maintain information security risk criteria. This includes, in particular, the criteria for risk acceptance and the performance of information security risk assessments.

Further, the process must ensure that "repeated information security risk assessments produce consistent, valid and comparable results," as the ISMS standard states. The following sub-items might be significant with a first step in mind:

  • Identify the information security risks
  • Analyze the information security risks
  • Evaluate the information security risks

The requirements in 6.1.3 call for establishing and applying a process to address the information security risk in order to achieve the following:

  • Select appropriate options for addressing the security risk, with respect to the results of the risk assessment
  • Determine all actions necessary to implement the selected options for addressing the security risk
  • Compare the defined measures with the controls specified in Annex A of ISO 27001 (target actions)
  • Prepare an applicability statement with regard to the reasons for (not) including the controls from Annex A
  • Formulate a plan for the handling of security risks
  • Obtain approval and acceptance of this plan from the risk owners

Reading tip: 

Also read the blog post on Annex A of ISO 27001

Annex A of ISO 27001 offers guidance

Annex A of the well-known management system standard ISO/IEC 27001 has an explicit normative character. It may be understood as a kind of checklist of 93 possible information security controls, focusing on the following four topics: 


A.5       Organizational controls (with 37 controls)
A.6       Personal controls (with 8 controls)
A.7       Physical controls (with 14 controls)
A.8       Technical controls (with 34 controls).

An organization can use Annex A to ensure that it has not overlooked any essential items to address security risks. However, it does not claim to be exhaustive.
 

Cover sheet for white paper ISO 27001 Annex A new controls with PDF
Loading...
Free White Paper

ISO 27001 – Controls in the New Annex A

With the revised DIN EN ISO/IEC 27001:2024 and the new, up-to-date information security controls in the normative Annex A, you can ensure that your organization is optimally protected against modern threats.


Benefit from our experts’ know-how. Learn all about the 11 new and 24 consolidated controls and what to consider during implementation.

Information security and quality management - what is the best approach?

ISO 27001 thus requires two separate processes for assessing and addressing information security risks. For the first step, however, these could be combined into a single process that specifically extends the risk assessment of quality management — in accordance with the aforementioned requirements — to include the aspect of information security. In this way, the two standards provide a solid foundation for implementing protective measures for data protection and IT security.

The extent to which this process ultimately addresses the individual requirements depends directly on the complexity of your company’s information landscape and the data worthy of protection. In any case, it is definitely advisable to have its effectiveness verified through an external audit. This is advisable, for example, as part of a certification audit of your quality management system according to ISO 9001 that is already planned.

Information security meets quality management - what are the benefits?

  • A process that takes a fundamental look at information security risks can serve as a first, important step toward a holistic management system for information security in accordance with ISO/IEC 27001.
  • By implementing such a process, top management strengthens awareness of information and data security (data protection) at all levels.
  • With the targeted consideration of information security risks, a company has the opportunity to uncover the need for action and to take appropriate measures (oriented on ISO 27001, Appendix A).
  • The risk assessment extended to include information security, for example as part of quality management, strengthens a company's overall risk-based approach.
  • Both the financial and human resources required for implementation and effectiveness testing are manageable.

 

DQS: Simply leveraging Quality

In the balancing act between dynamics and stability, certified management systems are becoming more and more important - a development that DQS feels in a positive way. Because successful companies and organizations use the findings from our audits to continuously improve their results. And they use our globally recognized certificates as objective proof of their quality capability. This creates trust - both internally and externally to your organization.

DQS issued Germany's first certificate for quality management in 1986. The first audit in August 1986 was based on a draft of the standard. In 1991, DQS received its first accreditation for ISO 9001/2/3 by the then TGA Trägergemeinschaft für Akkreditierung GmbH (today: DAkkS). Accreditation for information security certification according to the British standard BS 7799-2 followed in 2000. 

 

audit-gerber-hermsdorf-werner-korall-dqs.jpg
Loading...

Do you have any questions?

Contact us!

Free of charge and without any obligations

Trust and expertise

Our texts and brochures are written exclusively by our standards experts or auditors with many years of experience. If you have any questions to the author about contents or our services, please feel free to contact us.

Author

André Saeckel

Product manager at DQS for information security management. As a standards expert for the area of information security and IT security catalog (critical infrastructures), André Säckel is responsible for the following standards and industry-specific standards, among others: ISO 27001, ISIS12, ISO 20000-1, KRITIS and TISAX (information security in the automotive industry). He is also a member of the ISO/IEC JTC 1/SC 27/WG 1 working group as a national delegate of the German Institute for Standardization DIN.

Loading...

You Might Also Enjoy These Reads

Discover more articles that dive deep into related themes and ideas.
Blog
Loading...

NIS2 and ISO 27001: How ISO 27001 certification helps organizations meet the NIS2 cybersecurity requirements

Blog
Loading...

A best practice guide for creating effective ISMS objectives for ISO 27001

Blog
Loading...

ISO 42001 Certification in Hong Kong: Should Your Business Get Certified Now?