In the age of digitization, it is valuable information that must be preserved or protected above all. For companies, this means that alongside data protection, information security is an absolute must. The good news is: companies that have a certified quality management system in accordance with ISO 9001 have already created a good basis for the step-by-step introduction of fully comprehensive information security.
Information Security meets Quality Management
The topic of information security is not new. The dangers threatening the extensive information landscape in organizations have long been known. According to the April 2019 German BSI "Cyber Security Survey," 43% of large companies reported being affected by cyber security incidents in 2018.
For small and medium-sized enterprises, the figure was 26%. And according to the "Situation Report on IT Security in Germany 2021" from the German Federal Office for Information Security (BSI), cases of cybercrime have once again increased significantly. In the reporting period from June 1, 2020, to May 31, 2021, not only was there an increase of a good 22 percent in new malware variants (around 144 million), but the quality of the attacks also continued to rise considerably. In the process, many perpetrators exploited the Corona distress of many companies and people.
However, the security of confidential company information is still neglected. There is often a lack of caution and forethought when processing and storing information. Awareness of the consequences of data theft and its like is also far from sufficiently developed everywhere. In some places, companies are also reluctant to invest the time and effort required to effectively protect their sensitive information.
Step by step towards greater information security
But the effort required for data security doesn't have to be that great. The good news is that many companies do not have to implement a comprehensive information security management system in one fell swoop. For critical infrastructures (CRITIS), on the other hand, this is required by the German IT Security Act.
A step-by-step approach is also conceivable. This means that the first step, at least in companies that have a quality management (QM) system in accordance with ISO 9001, can be an update of the required risk-based approach - but already with a view to the corresponding requirements of the important information security standard ISO 27001.
ISO 9001 and ISO 27001 in the era of digitalization
The use of modern communication tools introduces entirely new considerations for managing documented information: availability, integrity, and confidentiality. An intriguing topic? Now available as a free white paper!
Content:
- Proper Handling of Documented Information
- Effectively Protecting Documented Information
- ISO 27001: The Foundation for Secure Digitization
Information security and quality management
ISO 27001 vs. ISO 9001: Where are the connections? First, it must be noted that the ISO 9001 quality management standard does require a risk-based approach across the board. However, the implementation of this management system requirement is largely up to your organization. For example, quality management does not require a separate process for risk assessment, but this is unquestionably too little with regard to information security. Nevertheless:
The risk assessment for quality management issues can easily be extended to the topic of information security.
To do this, it is helpful to look at the requirements for identifying and dealing with security risks of ISO 27001 for an information security management system (ISMS). Most aspects can be implemented by users of a quality management system with reasonable effort - as a first step on the way to holistic information security, mind you.
Information security - risks and opportunities
Both international standards, ISO 27001 for information security and ISO 9001 for quality management, deal with the relevant topics in Chapter 6.1 "Measures for dealing with risks and opportunities". In essence, the aim is to ensure three essential aspects in the management system:
- Achieving your organization's intended results
- Preventing or reducing undesirable effects
- Achieving continuous improvement through compliance with certain standards
With respect to information security, these are primarily the three essential protection goals:
- Loss of confidentiality
- Integrity of information
- Availability of information
The ISMS standard ISO 27001 specifies the following requirements (section 6.1.1):
- Determining risks and opportunities
- Planning measures to deal with the identified risks and opportunities
- Plan how the measures will be integrated into the company processes and implemented
Identifying and dealing with risks
The next subchapter (6.1.2) of ISO 27001 requires the establishment and application of an information security risk assessment process. This process must establish and maintain information security risk criteria. This includes, in particular, the criteria for risk acceptance and the performance of information security risk assessments.
Further, the process must ensure that "repeated information security risk assessments produce consistent, valid and comparable results," as the ISMS standard states. The following sub-items might be significant with a first step in mind:
- Identify the information security risks
- Analyze the information security risks
- Evaluate the information security risks
The requirements in 6.1.3 call for establishing and applying a process to address the information security risk in order to achieve the following:
- Select appropriate options for addressing the security risk, with respect to the results of the risk assessment
- Determine all actions necessary to implement the selected options for addressing the security risk
- Compare the defined measures with the controls specified in Annex A of ISO 27001 (target actions)
- Prepare an applicability statement with regard to the reasons for (not) including the controls from Annex A
- Formulate a plan for the handling of security risks
- Obtain approval and acceptance of this plan from the risk owners
Reading tip:
Also read the blog post on Annex A of ISO 27001
Annex A of ISO 27001 offers guidance
Annex A of the well-known management system standard ISO/IEC 27001 has an explicit normative character. It may be understood as a kind of checklist of 93 possible information security controls, focusing on the following four topics:
A.5 Organizational controls (with 37 controls)
A.6 Personal controls (with 8 controls)
A.7 Physical controls (with 14 controls)
A.8 Technical controls (with 34 controls).
An organization can use Annex A to ensure that it has not overlooked any essential items to address security risks. However, it does not claim to be exhaustive.
ISO 27001 – Controls in the New Annex A
With the revised DIN EN ISO/IEC 27001:2024 and the new, up-to-date information security controls in the normative Annex A, you can ensure that your organization is optimally protected against modern threats.
Benefit from our experts’ know-how. Learn all about the 11 new and 24 consolidated controls and what to consider during implementation.
Information security and quality management - what is the best approach?
ISO 27001 thus requires two separate processes for assessing and addressing information security risks. For the first step, however, these could be combined into a single process that specifically extends the risk assessment of quality management — in accordance with the aforementioned requirements — to include the aspect of information security. In this way, the two standards provide a solid foundation for implementing protective measures for data protection and IT security.
The extent to which this process ultimately addresses the individual requirements depends directly on the complexity of your company’s information landscape and the data worthy of protection. In any case, it is definitely advisable to have its effectiveness verified through an external audit. This is advisable, for example, as part of a certification audit of your quality management system according to ISO 9001 that is already planned.
Information security meets quality management - what are the benefits?
- A process that takes a fundamental look at information security risks can serve as a first, important step toward a holistic management system for information security in accordance with ISO/IEC 27001.
- By implementing such a process, top management strengthens awareness of information and data security (data protection) at all levels.
- With the targeted consideration of information security risks, a company has the opportunity to uncover the need for action and to take appropriate measures (oriented on ISO 27001, Appendix A).
- The risk assessment extended to include information security, for example as part of quality management, strengthens a company's overall risk-based approach.
- Both the financial and human resources required for implementation and effectiveness testing are manageable.
DQS: Simply leveraging Quality
In the balancing act between dynamics and stability, certified management systems are becoming more and more important - a development that DQS feels in a positive way. Because successful companies and organizations use the findings from our audits to continuously improve their results. And they use our globally recognized certificates as objective proof of their quality capability. This creates trust - both internally and externally to your organization.
DQS issued Germany's first certificate for quality management in 1986. The first audit in August 1986 was based on a draft of the standard. In 1991, DQS received its first accreditation for ISO 9001/2/3 by the then TGA Trägergemeinschaft für Akkreditierung GmbH (today: DAkkS). Accreditation for information security certification according to the British standard BS 7799-2 followed in 2000.
Trust and expertise
Our texts and brochures are written exclusively by our standards experts or auditors with many years of experience. If you have any questions to the author about contents or our services, please feel free to contact us.