Can Adiguzel

We are ISO 27001 certified. And it was no walk in the park.

We are a team that runs ISO 27001 audits, writes ISMS concepts, advises other companies and regularly explains how information security is done „properly“. And now we have had ourselves certified.

„Suddenly we were no longer the engineer – we were the building being tested for stability.“

The beginning: the moment of decision

We knew: if we want to stay credible, we have to be certified ourselves. Not because we had to. But because we want to lead by example. Because it is not enough to talk the talk – you also have to walk the walk.

So in the spring we made the decision: we would build our own ISMS and get certified – not just „somehow“, but to a DAkkS-accredited standard.

The reality: auditors don’t enjoy auditing themselves

And then the self-experiment began. We, who normally stand behind the checklists and risk matrices, suddenly sat in the meeting asking ourselves:

  • „How do we document this process in a way that makes sense?“
  • „Why do we actually do it this way?“
  • „Is this enough for the auditor?“
  • „Or is it too little… or too much?“

Spoiler: our biggest opponent was not the technology. It was our own standards.

The challenges: the processes you overlook every day – and that decide your audit

Our most important insights came from exactly those places where processes had long been taken for granted:

  • Onboarding of new team members that assumes knowledge but secures nothing
  • Risk analyses for tools that have „grown organically“
  • Regular communication that was never documented because „it has always worked“

After our own audit we know: process maturity does not show in complexity. It shows in whether a process is workable in daily business – and actually lived.

That is why we integrated all policies and processes for our daily work into our WIKI. We even moved the external publication of our policies directly into the WIKI.

ISO 27001 ISMS policies in the internal WIKI – 360 Digital Transformation

This does not only avoid the effort of jumping between different worlds (SharePoint, Google Drive, Confluence, etc.) – it also increases how much our people actually engage with it.

What we deliberately excluded

Not everything that is possible in ISO 27001 has to be inside your scope. Every company has to decide that for itself, based on its processes, activities and risks. That is why we deliberately left some controls out of scope:

  • 🔒 Physical security – as a remote-first company, we excluded several of the physical controls.
  • 💻 Software development – since we do not develop software, we removed the technical controls for software development from the scope.

We work transparently – so it was important to us to also tell you what we did not include. Because clarity matters, especially in audits.

Project Process from Gap Analysis to Certification

That was our path – from the GAP analysis to the certificate.

Six months later: the certificate in our hands

After six months of intensive work, many discussions, new routines and a few mistakes along the way (yes, those happened too), we can say with pride:

✅ We are ISO 27001 certified – DAkkS-accredited.

ISO 27001 Zertifikat – 360 Digitale Transformation, DAkkS-akkreditiert

And a certificate is not a one-off event: in June 2026 we also passed our first surveillance audit – the best proof that our ISMS does not just exist on paper, but works in everyday business.

The certificate does not just hang on the wall – it changes the way we work. Because now we too remember what it is like to fight your way through policies, to weigh documentation against productivity – and to ask yourself: „Why exactly are we doing this again?“

For trust. For clarity. For sustainable security.

Our learning: every serious consultant should be certified

When you are looking for an information security consultancy, please do not only ask: „How many clients have you supported?“ Ask as well: „How do you live information security yourselves?“

Because information security is not theory. It is a daily, sometimes tedious, but extremely effective process. And believe me: the certificate on the wall is only the symbol. The real value lies in the resilience of the organisation.

🔐 Certification is not an end in itself.
🔍 It forces you to take an honest look.
💡 And that is a good thing.

We now know even better how information security feels in practice – and we pass that experience on to our clients in our ISO 27001 consulting.

PS: If you are considering an ISO 27001 certification yourself – we know exactly how that feels. Talk to us: no buzzwords, no PowerPoint battles. 👉 We would rather talk about what actually works.

Want to start on your own first? Our ISO 27001 checklist gives you an overview of the most important steps.

About the Author

ISO 27001 certification experience

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX® consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

We are ISO 27001 certified. And it was no walk in the park. Read More »

VDA ISA 2027 – The Most Important Changes in the TISAX® Catalogue

On 1 July 2026, the German Association of the Automotive Industry (VDA) published the successor to VDA ISA 6 – the questionnaire behind every TISAX® assessment. Many expected it to be called „ISA 7.0“; officially it is named ISA 2027, because the VDA has switched to year-based version names. The structure largely stays the same – but the requirements become more binding, the supply chain moves into sharper focus, and prototype protection has been rebuilt from the ground up.

The key facts in numbers

  • Year-based naming: „2027“ instead of „7.0“ – an annual publication cycle from now on, for better planning.
  • Information security: 46 controls – the same as ISA 6. No control explosion, but 44 of the 46 controls were edited; in 25 controls, requirements change, are removed, or move.
  • Prototype protection: from 22 to 20 controls – the module has been completely restructured.
  • Data protection: unchanged – all 12 controls in chapter 9 are identical to ISA 6.
  • New framework mapping: ISA 2027 maps to NIST CSF 2.0 and ISO/IEC 27001:2022; the old references to ISO 27001:2013 are gone.

From recommendation to obligation

The most consequential change is a quiet one: requirements move from the should level (recommendation) to the must level (obligation). Two examples:

  • Control 1.1.1: making security policies available to employees and informing them about relevant changes used to be a should-requirement – in ISA 2027 it is mandatory.
  • Control 4.1.2: passwords according to the state of the art move from a side note into the regular requirements.

If your ISMS was built only to clear the must-threshold of ISA 6, this is exactly where the first new gaps will appear.

Chapter overview

ChapterWhat changesRating
1 – IS PoliciesNew crisis management (1.6.3), policy duties now mandatory (1.1.1)Major change
2 – Human ResourcesTeleworking rewritten with concrete must-requirements (2.1.4)Major change
3 – Physical SecurityA few clarificationsMinor change
4 – Access ManagementPassword and login rules tightenedMinor change
5 – IT SecurityMany small edits, additions for high protection needsMinor change
6 – SuppliersSupplier verification duties tightened, 1.2.4 becomes 6.1.3Major change
7 – ComplianceRewording onlyMinor change
8 – Prototype ProtectionFully restructured, 22 → 20 controlsMajor change
9 – Data ProtectionNo changesUnchanged

The supply chain moves into focus

Control 1.2.4 (external IT service providers) moves into the supplier chapter as the new control 6.1.3 – labelled a „Supplier Statement of Applicability“ (Supplier SoA) for the first time. The real tightening is in 6.1.1: for high protection needs, supplier security evidence must now be documented and reviewed regularly and on changes; for very high protection needs, a third-party audit or an adequate TISAX® label of the supplier is expected. Supplier management thus becomes one of the areas where the preparation effort will grow noticeably.

Prototype protection: rebuilt, not extended

Prototype protection is the biggest structural change: the five sections of ISA 6 (8.1 to 8.5) are merged into two (8.1 organisational8.2 physical and environmental security), controls are combined and outdated content is removed – from 22 down to 20 controls. If your assessment scope includes prototype protection, your documentation structure will need remapping even where the underlying measures stay the same.

What stays the same: data protection

Chapter 9 (data protection) is untouched – all 12 controls are word-for-word identical to ISA 6. If your scope includes the data protection module, nothing changes there.

When does VDA ISA 2027 apply?

The catalogue itself contains no transition date – the binding switchover date for TISAX® assessments is set by ENX. For the predecessor ISA 6, roughly six months passed between publication and mandatory use for new assessments. Until ENX announces the date, current assessments continue to run on ISA 6, and existing TISAX® labels do not automatically lose their validity.

What you should do now

  1. No panic migration: ISA 6 remains the assessed catalogue until ENX sets the date.
  2. Review the substantial chapters first: 1, 2, 6 and 8 – crisis management, teleworking, supplier management and prototype protection.
  3. Check the should-to-must promotions: requirements you previously treated as optional may now be mandatory.
  4. GAP analysis against the changed controls instead of reworking the whole catalogue.

How 360 Digital Transformation supports you

We guide you through the move to VDA ISA 2027 – from the GAP analysis through implementing the tightened controls and remapping prototype protection to preparing for the assessment. Foundations: the overview of TISAX® requirements and the TISAX® assessment. Still on ISA 6? You will find all the details in our article VDA ISA 6 – the most important changes. Happy to help as part of our consultancy for TISAX®.

Source: VDA – Information Security

About the Author

ISO 27001 certification experience

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX® consultant and ISO 27001 lead auditor. He has been working in IT project management for more than 11 years. His passion is information security for small and medium-sized businesses, and he helps these companies overcome their information security challenges with a practical consulting approach.

TISAX® is a registered trademark of the ENX Association. 360 Digitale Transformation has no business relationship with ENX. The mention of the TISAX® trademark does not constitute any statement by the trademark owner regarding the suitability of the services advertised here. TISAX® assessments for obtaining labels are carried out only by the audit providers listed on the ENX website.

VDA ISA 2027 – The Most Important Changes in the TISAX® Catalogue Read More »

ISO 27001 certification experience

Everything you need to know about TISAX® requirements: implementing and complying with certification standards

TISAX® stands for Trusted Information Security Assessment Exchange and is a registered trademark of the ENX Association. TISAX® is an assessment and exchange procedure for information security in the automotive industry.

It was developed by the German Association of the Automotive Industry and is now managed by the ENX Association. It provides a standardized approach to auditing and certifying the information security of companies operating in the automotive industry.

TISAX® is based on the international standard ISO/IEC 27001 and includes specific requirements of automotive manufacturers. We have compiled this article for you based on the experience of 50 projects.

The costs of implementing and certifying according to ISO 27001 vary depending on the company’s size and complexity, as well as other factors, which we will cover below.

Table of contents:

  • What is TISAX® and why is certification important?
  • What requirements must be met for TISAX® certification?
  • How can the TISAX® requirements be successfully implemented?
  • What steps are necessary to obtain TISAX® certification?

What is TISAX® and why is certification important?

This certification is crucial for companies in the automotive industry, as information security in this sector is particularly sensitive. By meeting the requirements of TISAX®, suppliers and service providers can prove that they meet the necessary standards for protecting information. Depending on the requirements, certification takes place at different assessment levels (Level 2 and Level 3). Companies that obtain TISAX® certification help to strengthen information security throughout the supply chain.

The ENX Association is an independent organization that accredits assessment providers.  It does not offer advice or support in preparation for the TISAX® assessment. Obtaining TISAX® certification requires considerable resources and financial means. The assessment objectives must be clearly defined and achieved to meet the requirements for TISAX®.

Basics and significance of TISAX®

The certification is divided into 3 levels, with Level 1 having the lowest requirements and Level 3 the highest. Companies in the automotive industry and their suppliers must fulfill the requirements for TISAX® certification in order to prove their information security. This is particularly important in the automotive industry, where the protection of sensitive data and prototypes is critical.

To obtain TISAX® certification, companies must meet the TISAX® requirements, which help to build trust with customers and partners. Assessment service providers offer advice and support in preparing for the TISAX® assessment to ensure that companies achieve the objectives set.

The requirements for TISAX® levels 1 to 3 can be described as follows:

TISAX® Level 1:

Companies can carry out the TISAX® Assessment Level 1 themselves via a self-assessment. For TISAX Level 1, an assessment of the company based on the ISA questionnaire is required, but this is not reviewed. Since the measures are not checked objectively and the company alone is responsible for the results, this has little significance in practice.

TISAX® Level 2:

The security requirements of a company are classified as high at Level 2. In a Level 2 assessment, the company’s self-assessment is confirmed by a TISAX assessment company approved by ENX. The audit is carried out based on the company’s documentation.

TISAX® Level 3:

Level 3 according to TISAX® means that the need for protection is classified as “very high”. It is the highest security level for companies in the automotive industry. At Level 3, on-site inspections and live interviews are carried out by an auditor. Documents and evidence are checked, local conditions are considered, process implementation is observed and unplanned interviews are conducted with process participants. An accredited auditor conducts an on-site assessment of the maturity level of the Information Security Management System (ISMS) at each of the company’s locations.

These descriptions provide an overview of the respective expectations and the level of security that organizations must achieve at the various TISAX® levels.

Advantages of TISAX® certification

By meeting the requirements for information security in the automotive industry, car manufacturers can ensure that their ISMS is managed and monitored.

The VDA-ISA questionnaire serves as a central platform for defining the requirements and monitoring the entire process. Suppliers and service providers can ensure that they achieve all assessment objectives and implement continuous improvement in their system by preparing for the TISAX® assessment. In this way, TISAX® certification helps to standardize and document the process.

What are the differences between TISAX® and ISO 27001?

The differences between TISAX® and ISO 27001 lie mainly in the specific objectives that must be met. While ISO 27001 defines general requirements for information security management systems, the TISAX® requirements are tailored specifically to the automotive industry.

While there is no standardized process for ISO 27001 certification, there are proofs of the requirements for TISAX® that must be fulfilled. Companies must fulfill several requirements to obtain TISAX® certification, while ISO 27001 specifies an established process that must be followed.

What do TISAX® and ISO27001 have in common?

The ISO 27001 and TISAX® certifications have significant similarities. This makes it possible to work on both certification projects in parallel and manage them together, although this certainly means additional work.

We have written a detailed post on the differences and similarities between ISO 27001 and TISAX®.

TISAX® certification already covers up to 70% of the requirements of the new NIS2 directive.

What requirements must be met for TISAX® certification?

The TISAX® requirements are defined in the requirements catalog of the German Association of the Automotive Industry. An assessment according to TISAX® must be carried out in which the legal requirements and the associated requirements are checked. The ISA questionnaire serves as a testing and exchange mechanism.

The maturity model distinguishes between 6 maturity levels:

Maturity level

Terminology

Description

0

Incomplete

There are no documented security measures or guidelines. Information security is not considered or neglected.

1

Performed

There are some documented security measures, but clear policies and processes are lacking. Information security is poorly managed and inconsistent.

2

Managed

There are documented security guidelines and processes, but their implementation is incomplete or inadequate. Information security is considered sporadically.

3

Established

Security measures are largely documented and implemented, but regular reviews and improvements are lacking. Information security is consistent.

4

Predictable

Security measures are documented, implemented, and regularly reviewed. There is a formal process for security assessment and improvement. Information security is proactively managed.

5

Optimizing

The security measures are documented, implemented, and continuously improved. There is a formal process for the ongoing monitoring, measurement, and optimization of information security.

Requirements for information security according to TISAX®

Companies must meet certain expectations about structure and information security to receive TISAX® certification. These include the defined objectives, which follow a standardized process.

Companies must fulfill the requirements of the VDA’s ISA questionnaire if they intend to obtain TISAX® certification.

The certification confirms that the company has taken the necessary measures to ensure information security. It also confirms that the company explicitly follows the requirements according to the TISAX® questionnaire. This enables the company to gain a competitive advantage and build trust with customers and partners.

An overview of the VDA ISA questionnaire and its significance for the automotive industry.

The requirements for information security are defined in the ISA questionnaire. The ISA questionnaire is a tool used by the automotive industry to assess and improve information security within companies.

It provides a structured approach to identifying security risks and implementing appropriate measures to protect sensitive information. The importance of this catalog for the automotive industry lies in its ability to help companies meet the increasing requirements for data protection and information security.

Audit objectives and protection requirements in the TISAX® audit

There are eight TISAX® audit objectives, each of which defines specific requirements for TISAX®certification: Two for the security of information, four for the protection of prototypes and test vehicles, and a further two for data protection.

Objective

Explanation

Handling information with different protection requirements

Appropriate security measures must be implemented to ensure that information is classified, processed and stored according to its protection needs. This can be achieved through encryption, access controls and information classification policies.

Protection of prototype components

Prototype components must be protected to prevent unauthorized access and theft. This can be achieved through physical security measures such as secure storage and access restrictions.

Dealing with prototype vehicles

Prototype vehicles must be protected from unauthorized access to ensure the confidentiality of development projects. Access controls and monitoring systems are crucial here.

Dealing with test vehicles

Test vehicles must be protected according to their sensitivity in order to minimize potential safety risks during the test phase. Access controls and monitoring systems are necessary.

Organization of events with prototype vehicles

At events where prototype vehicles are presented, security measures such as access controls and monitoring systems must be implemented to prevent theft or damage.

Data protection

Data protection regulations must be adhered to in order to protect personal data from unauthorized access, loss, or misuse. This includes measures such as data protection guidelines, access controls, and data protection training. The basis is the GDPR.

Personal data protection

Personal data must be protected according to the applicable data protection regulations. This includes compliance with data protection laws such as the GDPR and the implementation of appropriate technical and organizational measures to protect this data.

The TISAX® certification process is complex and requires regular renewal every three years through recertification.

How can the TISAX® requirements be successfully implemented?

Tips for documentation and verification

Careful documentation and verification are essential for the successful implementation of TISAX® requirements. The first step is to conduct a detailed analysis of all requirements to ensure that all relevant aspects are covered.

  1. Clear documentation of all the actions taken is crucial to complete the certification process successfully. Storing all relevant evidence in a well-organized system is recommended so that it can be presented quickly if required.
  2. In addition, regular reviews of the measures implemented should be carried out to ensure compliance with the specified targets in the long term. Companies that have followed an established process can hold their own against companies without certification.
  3. There is no predefined process to fulfill the requirements. However, you should have followed a documented process. The Information Security Assessment Catalog supports companies in meeting the TISAX® requirements, building a secure system, and maintaining it in daily operations.

Consultants can help to fulfill the requirements for certification according to TISAX® in the audit

  • Consultants help companies prepare for TISAX® certification with a gap analysis to meet the stringent assessment objectives.
  • They can help to develop and implement security measures and data protection standards to meet the TISAX® requirements.
  • Consultants also offer training courses and workshops to inform employees about the requirements of TISAX® and to prepare them for the audit.
  • They can help companies optimize internal processes to meet TISAX® requirements and assist in preparing the required documentation.
  • While consultants prepare companies for the audit, they do not conduct formal audits or prepare official audit reports.

The role of audit service providers in the TISAX® certification process

  • Audit providers are responsible for conducting the actual TISAX audits, also known as assessments.
  • They must be officially approved and qualified by the ENX Association to carry out the task.
  • Please note that the ENX Association assumes no responsibility for the specifications explicitly defined in a TISAX® manual.
  • Their main task is to check the TISAX® requirements and assess whether a company meets the requirements.
  • A standard process is followed to ensure that the overall system is integrated.
  • Auditors conduct audits to ensure that the company has implemented the necessary security measures and meets data protection standards.
  • On completion of the audit, auditors prepare a report containing their audit results and any recommendations for improvement.

Overall, auditors and consultants often work hand in hand, with consultants helping companies prepare for TISAX certification, while assessors carry out the formal audits and evaluate compliance.

What steps are necessary to obtain TISAX® certification?

ISO 27001 certification experience

What is the process from gap analysis to successful TISAX® certification?

  1. GAP analysis: In this phase, a comprehensive analysis is carried out to identify the gaps between the current processes and the requirements of the TISAX® standards. This helps to develop a detailed action plan.
  2. ENX registration: Registration with ENX takes place after the GAP analysis. This is a necessary step to start the certification process. We will be happy to help you with the registration process.
  3. Auditor selection: This is where you select an ENX-approved auditor to perform the TISAX® assessment. The choice should be based on experience, expertise, and cost. With our extensive experience, we can assist you in the selection process.
  4. Audit preparation: In this phase, you prepare your company for the upcoming audit. This includes training staff, reviewing security policies and procedures, and ensuring all requirements are met.
  5. ISMS establishment and implementation: This involves implementing your company’s information security management system (ISMS) and establishing security policies, procedures, and controls.
  6. Workshops: We conduct workshops with you to increase awareness and understanding of the requirements of the TISAX® standards. They also serve to train staff in the relevant security practices.
  7. Self-assessment: Before the actual audit, you carry out a self-assessment. This allows you to assess your maturity level for the audit and close any gaps.
  8. TISAX® Audit: Finally, the TISAX® audit takes place. The selected assessor will evaluate compliance with the TISAX® standards. After a successful audit, you will receive the desired TISAX® label.

Clearly described, documented and verifiably practiced processes make it easier for everyone involved in the organization to understand and implement the steps to successful TISAX® certification. We would be happy to support you in this process.

The process from preparation to successful TISAX® certification begins with an understanding of the assessment objectives and requirements of the ISA requirements catalog. The requirements must be carefully implemented in order to create a solid foundation for certification.

Achieve a comprehensive understanding of TISAX® compliance so that all relevant aspects are covered. Supporting measures such as training and internal audits are also a must to establish and maintain TISAX® in daily business operations. Ultimately, consistently implementing these steps leads to successful certification and demonstrates a company’s commitment to sensitive data security and protection.

The expenditure and costs associated with TISAX® certification

The expenditure and cost of a TISAX® certification can vary depending on the company and its requirements. Estimating the potential costs and effort in advance and planning accordingly is important to ensure a smooth certification process.

The maturity level of your company is decisive for the costs. The project duration and the resulting costs range from 3-12 months and 25,000 – 50,000€. If you would like to learn more about the cost of TISAX®, please click here to read our Blog Post.

Can small companies meet the requirements of TISAX® certification?

Yes, small companies definitely can meet the requirements of TISAX®. The ISA questionnaire is designed in such a way that even small companies can work with it. The TISAX® requirements should be seen as guidelines that can be flexibly implemented to achieve adequately the desired audit objectives and the required protection.

Audit service providers determine the appropriateness for each company individually. However, both the establishment of an ISMS and the audit itself require a certain amount of effort and cost. For this reason, we advise micro-enterprises to consider whether the effort and potential benefits of TISAX® certification are economically justifiable.

Our practical tips for meeting the TISAX® requirements as more than 30 projects

The processes in which owners must be involved in a TISAX® project are listed below:

  • Management: A TISAX® project is not possible without management support. The first requirement is therefore fulfilled if management support is available.
  • HR: Efficient hiring, the definition of sensitive activities, and on-off boarding processes are the important parts of a TISAX® project. The planning and implementation of training courses are also part of the HR department’s responsibilities.
  • Facility management: Physical security, security zone concept measures, emergency plans, and emergency drills are must-haves for successful TISAX® projects.
  • IT: Self-explanatory. The IT is responsible for 60% of a TISAX project. Regardless, the interfaces between IT and other departments must be defined and documented.
  • Purchasing: Information security relevant suppliers and non-disclosure agreements are critical parts of a TISAX® project.
  • Compliance: The data protection officer (DPO) – if available – and, depending on the company size, the legal department should participate.
  • Time: A TISAX® project and the maturity of an ISMS take time. A successful TISAX® project should be expected to take at least 6 months. For larger companies and depending on the maturity of the existing processes, this period can be up to 12 months.

About the Author

ISO 27001 certification experience

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX® consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

Everything you need to know about TISAX® requirements: implementing and complying with certification standards Read More »

ISO 27001 certification experience

ISO 27001 Checklist for Successful Certification: Your Implementation Guide

ISO 27001 is the leading international Information Security Management System (ISMS) standard. In our article, you will discover how to successfully prepare for ISO 27001 certification using a detailed ISO 27001 checklist. We have structured this guide step-by-step to show you how to improve your information security, ensure compliance, and build trust with your partners and customers.

Table of contents:
  1. Why is the ISO 27001 standard important?
  2. How do I start implementing an ISMS?
  3. How do I manage the ISMS documentation?
  4. What should the ISO 27001 checklist include?
  5. Use of ISO 27001 checklists
  6. How do I define the application scope for ISO 27001?
  7. What steps are involved in a risk assessment following ISO 27001?
  8. How do I prepare for an internal audit?
  9. What is an external audit and how to succeed in it?
  10. How do I obtain the ISO 27001 certificate?

Why is the ISO 27001 standard important?

ISO 27001 is an internationally recognized standard developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).

It provides a comprehensive framework for managing sensitive company information and ensures its security by implementing an information security management system.

Benefits of ISO 27001 certification

ISO 27001 certification offers numerous benefits, including:

  • Improved risk management: Systematically identifying and assessing risks allows you to manage threats proactively.
  • Increased customer confidence: Customers and partners appreciate the high- security standards demonstrated by ISO 27001 certification.
  • Competitive advantage: Organizations with ISO 27001 certification distinguish themselves from competitors and gain access to new business opportunities.
  • Compliance with legal requirements: Certification helps companies to meet legal and regulatory requirements for information security, and thus ensure compliance with regulations.
  • Protection of company data: An organization’s ISMS protects sensitive company information from unauthorized access, loss, or theft.
  • Increased efficiency and structure: ISMS implementation leads to clearly defined processes and structures that increase efficiency in the company.
  • Reduction of security incidents: Security incidents can be minimized through preventive measures and continuous monitoring.
  • Improved business continuity: A robust ISMS helps to ensure business continuity if security incidents or disasters occur. Regularly conducting ‘lessons learned’ reviews helps to avoid future incidents.
  • Cost savings: By preventing security incidents and protecting against data loss, potential financial losses can be avoided.
  • A better image and reputation: Certification strengthens the company’s image and reputation as a reliable and safety-conscious partner.
  • Easier access to international markets: ISO 27001 implementation is recognized worldwide and facilitates access to international markets and business partners.
  • Continuous improvement: The standard requires continuous review and improvement of the ISMS, resulting in the ongoing development of information security measures.
  • Employee motivation: Employees become more aware and motivated to take security measures seriously and implement them, which leads to a better security culture in the company. With their enhanced know-how, employees can also improve the protection of their private data.

How do I start implementing an ISMS?

Establishing an information security management system is the first step towards ISO 27001 certification. This requires careful planning and a structured approach. We have listed a few points here. (Suggested follow-up: read our article on how to set up an ISMS)

Defining the scope

The scope of your information security management system should be clearly defined. This includes identifying the information, processes, and departments within the scope. A precisely defined scope facilitates the allocation of resources and ensures that all relevant areas are covered.

While the scope defines where the ISMS is applied, the Statement of Applicability (SoA) as per Annex A, documents which specific security controls are implemented within this scope and which are not, along with the respective justifications. Thus, the SoA ensures the defined controls are systematically aligned with the identified risks and requirements.

Conducting a risk assessment

A thorough risk assessment is crucial to identify potential threats and vulnerabilities in your information security management system. A systematic risk analysis helps you to assess risks and implement appropriate security measures.

How do I manage the ISMS documentation?

Managing ISMS documentation is an ongoing process that should be regularly reviewed and updated. A best-practice structure for optimal applicability ensures all relevant guidelines and processes are included. Additionally, the documentation should be regularly backed up and updated to reflect any changes in the company or legal regulations.

Creating and maintaining documentation

Ensure all policies, procedures, and records are up-to-date and easily accessible. This will facilitate compliance with ISO 27001 Certification requirements and support the continuous improvement of your ISMS.

What should the ISO 27001 checklist include?

A comprehensive ISO 27001 checklist is an indispensable tool to ensure that you consider all the necessary steps and requirements during the certification process. Here are some of the most important elements:

Creating guidelines and procedures

ISO 27001 requires the documentation of information security policies and procedures. These should be clearly defined and easily accessible to ensure all employees understand and follow the guidelines. They should also be aligned with your organization’s needs.

Employee training and awareness

Regular training and awareness-raising measures are essential to increase employees’ information security awareness. This helps to identify potential threats and consistently implement security guidelines.

You can download our complete checklist here.

Use of ISO 27001 checklists

Use checklists to ensure that all necessary documentation is available and regularly reviewed. This will help you to maintain an overview and improve the efficiency of your ISMS.

How do I define the application scope for ISO 27001?

The precise definition of the scope of application is a critical step in the ISMS implementation.

Identification of relevant information

Determine which information falls within the scope of your ISMS, such as customer data, internal reports, financial information, and other sensitive data. This identification occurs during the scope definition and serves as the basis for selecting the security controls documented in the Statement of Applicability (SoA).

The Statement of Applicability (SoA) then documents which specific security controls from Annex A are implemented within this defined scope and justifies the selection or exclusion of each control.

Consideration of physical and organizational boundaries

Define the physical and organizational boundaries of your ISMS. This includes the premises where the data is processed and the departments and employees who have access to it.

What steps are involved in a risk assessment following ISO 27001?

Risk analysis and assessment are vital in the ISO 27001 certification process. Here are the key steps:

Identification of risks and threats

Identify potential risks and threats to your information security resources through interviews, questionnaires, and workshops. This is the only way to protect your assets.

Assessment and prioritization of risks

Assess the identified risks based on their probability and potential impact, prioritize them according to their severity, and develop appropriate risk mitigation measures.

How do I prepare for an internal audit?

Internal audits are a key part of the ISO 27001 certification process. They help you to verify compliance with ISO 27001 requirements and identify areas for improvement. An experienced ISO 27001 consulting team can assist you with the following points.

Planning and conducting internal audits

Create an audit plan and carry out regular internal audits to check the effectiveness of your information security management system. Document the results and take measures to fix any vulnerabilities.

Training of employees and management

Your employees and management should have the necessary knowledge and skills to conduct effective audits with external help. Training and certification can help achieve this.

What is an external audit and how to succeed in it?

An external audit is conducted by an independent certification body to check the conformity of your ISMS with the ISO 27001 requirements.

Preparation for the external audit by ISO 27001

If you want to be certified to ISO 27001, prepare thoroughly for the audit and provide all the necessary documents and evidence. Ensure that all employees are familiar with the processes and procedures and can answer the auditor’s questions correctly.

Conducting the external audit according to ISO standards

During the audit, the auditor will review your documentation, and conduct interviews and inspections to confirm compliance with ISO 27001 requirements. Upon completion of the audit, you will receive a report with the results and recommendations.

How do I obtain the ISO 27001 certificate?

Once you have successfully passed the audit for ISO 27001 certification, you will receive the ISO 27001 certificate. This certificate is a formal proof of compliance with the ISO 27001 requirements and shows that your ISMS meets international standards.

Summary for your ISO 27001 project

    • ISO 27001 is an internationally recognized information security management system (ISMS) standard.
    • Introducing an ISMS requires careful planning, risk assessment, and documentation.
    • An ISO 27001 checklist helps you to comply with the requirements and prepare for audits.
    • Internal and external audits are crucial for certification and continuous improvement.
    Take the first step towards ISO 27001 certification and strengthen information security in your organization. Use this guide and checklist to make the process simple and secure.

About the Author

ISO 27001 certification experience

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

ISO 27001 Checklist for Successful Certification: Your Implementation Guide Read More »

ISO 27001 certification experience

NIS 2 Requirements in Information Security – How companies should prepare for the new regulation

With the introduction of NIS 2, companies must comply with new cyber security standards. Failure to act now will jeopardize your own security and competitiveness, as well as failing to meet legal requirements. Take this opportunity to strengthen your systems and secure the trust of your customers and partners. In our article, we explain in detail the new requirements, the extended scope of the application, and who is affected by the new NIS 2 requirements.

Table of contents:

From October 2024, the new requirements of the NIS 2 directive apply to IT security

The NIS 2 directive officially entered into force in October 2024 after being adopted by the European Parliament in 2022. Transposition into national law is mainly the responsibility of the legislative bodies, in particular the Federal Ministry of the Interior and Home Affairs (BMI), in cooperation with the Federal Parliament (Bundestag) and Federal Council (Bundesrat), to strengthen security standards in the network and information systems.

Companies must take several steps to comply with the Directive by that date. With NIS-2, these requirements affect a broader range of industries and represent extended obligations in the cybersecurity field.

Transposition into national law in October 2024

  • Implementation deadlineBy October 2024, all EU member states must have transposed the NIS 2 guideline into national law. As of this date, companies must comply with the new, stricter cyber security requirements. No grace will be given!

  • Validity of the new regulations: From October 18, 2024, the latest safety requirements will be binding for companies that fall within the scope of NIS 2. This also includes companies not previously affected by the original NIS Directive.

1) New requirements for affected companies in the automotive industry:

Extended reporting obligations for security incidents in the NIS 2 directive:

Companies in the automotive industry must ensure that they report cyber incidents to the BSI quickly and effectively to ensure the effectiveness of their security strategies.

The BSI receives these reports, evaluates them, and coordinates the response to the security incident if necessary. It ensures that incidents are dealt with quickly and effectively to prevent major damage.

The NIS 2 directive requires incidents to be reported to the relevant authorities within 24 hours of detection. This includes not only reporting security incidents but also an initial assessment of the situation.

A detailed report on the incident must be submitted within 72 hours, containing information on the cause, the systems affected, and the measures taken. This strict deadline ensures that threats can be detected and countered early to prevent major damage.

Stricter information security requirements in the automotive industry

The NIS 2 directive extends the security focus to all IT and OT (operational technology) systems used in the automotive sector.

This means that not only traditional IT systems such as servers, networks, and end devices need to be protected, but also production systems. As modern vehicles are increasingly connected to the internet and become part of a global network, they must be protected against cyber attacks just like other IT systems. You must ensure that all systems are checked for vulnerabilities and that regular security updates are carried out.

Supply chain management for critical infrastructure:

A core element of the NIS 2 directive is the protection of the entire supply chain. Companies in the automotive industry work with numerous suppliers and service providers who may have access to sensitive data or critical infrastructure.

The directive requires companies to actively monitor the security of their supply chain and ensure that all partners involved implement appropriate security measures. This can be done through contracts, audits, and regular security assessments to improve cyber hygiene. A vulnerability at one supplier can potentially jeopardize the entire supply chain, which is why this topic should be taken very seriously.

Risk management for critical infrastructure - NIS 2 requires constant monitoring in the automotive industry

As a company, you need to introduce specific risk management for critical infrastructures tailored to the particular threats in the automotive sector.

Risks in the supply chain must be constantly monitored and managed to avoid security incidents. This means that risks to all IT and OT systems that are essential to operations and production must be regularly identified, assessed, and mitigated.

This risk management must be dynamic and adapt to the constantly changing threat landscape. Companies need to develop processes to respond quickly to emerging risks. Their systems must be robust enough to fend off cyber attacks.

Consistent implementation is required for compliance responsibility

Every company must appoint a person responsible for ensuring compliance with the NIS 2 directive. This role is often assumed by a Chief Information Security Officer (CISO) or Information Security Officer (ISO), who is responsible for implementing the security guidelines throughout the entire company. These officers are often supported by experienced consultants.

They also monitor compliance with the new requirements and are the point of contact for the competent authorities. This person bears considerable responsibility, as violations of the directive can lead to significant penalties.

Sanctions for non-compliance with NIS 2 requirements:

The NIS 2 directive introduces stricter sanctions to ensure compliance with security regulations. Non-compliance can result in fines of up to 2% of the company’s global annual turnover.

These high penalties are intended to motivate companies to take the requirements seriously and take proactive measures to protect their systems. In addition, breaches of security standards can lead to reputational damage that could have a serious long-term impact on business, especially in a highly regulated sector.

2) Essential requirements that are new compared to ISO 27001

Systematic threat analysis as a new requirement:

While ISO 27001 already requires a risk assessment, NIS 2 goes one step further by prescribing a systematic and regular threat analysis. Companies must continuously monitor the threat landscape and adapt their protective measures to new threats.

These analyses must be documented and integrated into the company’s security strategy. The aim is not only to identify existing risks but also to anticipate possible future threats and take proactive measures.

Obligatory cooperation with public administration (authorities):

A key difference to ISO 27001 is the mandatory cooperation with and between companies and authorities as well as other players within the industry.

The NIS 2 directive requires the exchange of information on threats, incidents, and best practices. This is intended to increase collective security and ensure that all affected companies can react quickly to new threats. Companies are encouraged to set up appropriate communication channels and participate in initiatives to improve cyber security.

Protection of critical services and systems:

The NIS 2 directive requires companies to provide special protection for critical services and systems and important facilities that are of national interest. In the automotive sector, these could be systems required for safety-critical components production or autonomous vehicle operation. Such systems should be protected through strengthening measures like multi-factor authentication.

These systems must be specially secured and monitored to ensure that their integrity and availability are not jeopardized by cyber attacks. This often requires additional security measures that go beyond the basic requirements of ISO 27001.

Industry-specific mandatory awareness training for employees

The NIS 2 directive emphasizes the importance of regular and specific training for all employees. While ISO 27001 provides for general security awareness programs, NIS 2 requires that this training is tailored to the specific threats and challenges of the industry to increase effectiveness.

Employees must be informed not only about basic security principles but also about current threats and correct incident response mechanisms. This training needs to be updated regularly to reflect the latest developments in the cyber security landscape.

Increased reporting obligations through regular safety reports to authorities

NIS 2 introduces stricter reporting obligations that go beyond the requirements of ISO 27001. Not only must incidents be reported to the BSI, but regular reports on their security measures, risk assessments, and threat analyses must also be submitted.

These reports must be detailed and enable the authorities to assess the company’s security situation and request additional measures if necessary. The increased transparency should help develop a comprehensive understanding of the cyber security landscape and take targeted protective measures.

Extended due diligence by reviewing cyber security measures at suppliers

The NIS 2 directive introduces an extended due diligence that goes beyond the requirements of ISO 27001. Companies are obliged to check not only their own systems but also those of their suppliers and service providers for security risks.

This requires close cooperation with all parties involved in the supply chain and the implementation of security standards at all levels. Companies are required to ensure that their partners implement similar security measures and that these measures are regularly reviewed. Our ISO 27001 consultants will be happy to help you.

These detailed requirements illustrate how NIS 2 is changing and strengthening the cybersecurity landscape for businesses, particularly in the automotive sector. A thorough implementation of this directive is crucial to countering the growing threats in the networked world effectively.

The NIS 2 requirements bring new responsibilities for management and specific measures per sector

1. Extended scope and sector-specific requirements

  • Extension to new sectors: The NIS 2 directive extends the scope of application to more sectors than before. These include the healthcare industry, digital infrastructure, and medical equipment manufacturers
  • Sector-specific requirements: Each industry has its specific cybersecurity challenges. Companies have to develop sector-specific security measures that are tailored to their particular risks and threats.

2. Responsibility at the management level

  • Management liability and responsibility: Senior management is fully responsible for compliance with cybersecurity regulations. Managers must ensure that all requirements of the NIS-2 directive are implemented in the company. They can be held personally accountable for violations.
  • Establishing governance structures: By establishing clear governance structures, companies define their responsibilities for cyber security. This includes establishing cyber security committees and appointing persons responsible for implementing and monitoring security measures.

3. Measures to increase resilience

  • Resilience strategies: Companies are required to develop resilience strategies that go beyond IT systems protection. These strategies must be designed to ensure the company remains operational during and after a cyberattack, allowing it to resume normal operations quickly.
  • Business Continuity Management (BCM): Companies and organizations must develop plans to ensure that critical business processes can continue not only in the event of IT failures but also in the event of all failures (electrical or other exceptional situations).

4. Technical and organizational measures

  • Data Encryption: Strong encryption technologies should be used to protect sensitive data both at rest (data at rest) and in transit (data in transit). All critical data stored or transmitted in their systems must be secured using suitable encryption methods. This significantly reduces the risk of data loss or theft in case of cyberattacks.
  • Technical protective measures: In addition to general IT security precautions, specific measures, such as continuous network monitoring and the implementation of intrusion detection systems (IDS), are also required. These measures are necessary to detect and avert potential threats at an early stage.

  • Organizational measures: Organizational structures must be geared towards rapid response and effectively managing security incidents. This includes the establishment of incident response teams and the regular implementation of emergency drills.

5. International cooperation and exchange of information

  • Cooperation between EU member states: The new guideline promotes increased cooperation among EU member states. Large companies with an international presence must be prepared to cooperate across borders to effectively counter threats.
  • Information exchange at the EU level: The NIS 2 directive calls for the active exchange of information on cyber threats and security incidents at the European level. The necessary channels must be set up to support this exchange.

6. Extended documentation and verification obligations

  • Extended obligations to provide evidence: Affected companies must keep comprehensive documentation that proves compliance with the NIS 2 requirements. This documentation must be updated regularly and submitted to the competent authorities if required.
  • Retention periods for documentation: There are strict requirements for retaining security-related documentation. Companies are responsible for ensuring these documents are stored and easily accessible for a specified period.

7. Security requirements for cloud services and third-party providers

  • Cloud security: There are clear requirements for the security of cloud services. Cloud solutions used must meet the highest security standards and be regularly checked for vulnerabilities.
  • Third-party obligations: The security of the entire supply chain is crucial. Regularly check whether your third-party providers have also implemented strict security measures.

8. New requirements for reporting and communication channels

  • Procedures for reporting security incidents: Affected companies and organizations must establish clear and effective procedures for reporting security incidents. These procedures must be organized so that security incidents are reported quickly and completely to enable a timely response.
  • Extended reporting to supervisory authorities: In addition to incident reporting requirements, companies must also submit regular reports to regulators on the status of their cybersecurity measures and risk management.

9. Alignment and integration with other safety standards

  • Integration with existing standards: Companies must adapt their security measures so that they meet the requirements of the NIS-2 directive as well as other relevant standards such as ISO 27001 or TISAX®. This requires careful analysis and adaptation of current processes.
  • Standardization of security processes: Companies should standardize their cybersecurity processes to avoid redundancies and facilitate compliance with different standards. This leads to more efficient security operations and better compliance.

10. Future developments and adaptability

  • Adapting to future threats: The threat landscape is constantly evolving. Companies need to develop dynamic security strategies that are flexible enough to respond to new threats and technologies.
  • Further development of the directive: NIS 2 may evolve to respond to future challenges. Companies should, therefore, continuously review their security strategies and adapt them to new legal requirements.

About the Author

ISO 27001 certification experience

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

NIS 2 Requirements in Information Security – How companies should prepare for the new regulation Read More »

ISO 27001 certification experience

What are the responsibilities of an Information Security Officer (ISO)?

The duties of an information security officer (ISO) are diverse and essential for ensuring information security in the company, minimizing risks, and meeting legal requirements.

The ISO plays a central role in protecting sensitive data and systems, from implementing effective security policies to training employees.

Duties of an Information Security Officer

The role of an information security officer is multifaceted and crucial to ensuring robust information security in companies. Its main duties include:

1. Development and implementation of an ISMS:

Information security officers implement an information security management system (ISMS) according to recognized standards such as ISO 27001 or TISAX. In doing so, they create comprehensive policies, procedures, and guidelines that serve as the basis for effective information security. This is particularly important for structuring organizational processes and clearly defining responsibilities.

2. Monitoring and control:

Regular reviews and audits of information security measures are essential. The ISO ensures that legal regulations and internal security guidelines are consistently adhered to. This continuous monitoring helps to identify potential vulnerabilities at an early stage and react in time. In addition, the security strategy is often based on the recommendations of the German Federal Office for Information Security (BSI) in order to comply with current standards and best practices in the IT security field in information technology.

3. Training and awareness-raising:

Employee training is a key component of the security strategy. The external ISO conducts regular training sessions to raise awareness about information security. Current threats, risks, and best practices are covered in order to promote a security culture within the company.

4. Risk management:

The ISOs identify and assess security risks that may affect the company. They then outline tailored proposals for risk mitigation and implement technical and organizational measures to improve the security situation.

Identifying, assessing, and managing risks associated with information security is critical. The ISO places particular emphasis on data confidentiality by proposing suitable measures to prevent unauthorized access to sensitive information. This includes technical and organizational measures to ensure company data integrity and confidentiality.

5. Consulting the management

As a consultant to company management, the external ISO provides valuable insights into all aspects of information security. They prepare detailed reports on the current security status and formulate recommendations for improving security strategies in order to strengthen the company’s resilience.

6. Support for audits and certifications:

Consultant Information Security Officers actively support companies in preparing for external audits and certifications, such as ISO 27001. They accompany and coordinate the entire audit process to ensure all requirements are met.

7. Information security incident management:

An important aspect of the security strategy is the development of emergency plans and incident response processes. The ISO assists in responding to security incidents, whether a data breach or a cyber attack, and ensures that the company can act quickly and efficiently.

Is there a legal obligation to appoint an Information Security Officer (ISO)?

The obligation to appoint an information security officer (ISO) in Germany depends on various legal provisions and industry-specific requirements. Companies must always analyze their situation to determine whether such an appointment is required. Below, we provide an overview of the main regulations and industries in which the appointment of an ISO may be necessary.

1. Critical infrastructures (KRITIS)

Companies acting as critical infrastructure operators (KRITIS) are obliged to implement information security measures by the IT Security Act (IT-SiG). These companies, operating in sectors such as energy, healthcare, transportation, and finance, bear a particular responsibility. As a failure of their IT systems would have far-reaching consequences for society, they are obliged to ensure the highest level of IT security.

2. The NIS 2 Directive

The EU’s NIS 2 Directive significantly expands the security requirements for companies in essential sectors. This directive, which aims to improve the security of networks and information systems, requires companies in certain sectors to strengthen their IT security. This often includes appointing information security officers responsible for implementing and monitoring information security measures. The NIS2 Directive affects a wide range of sectors, from utilities and transport to communications and healthcare facilities.

3. Data protection (GDPR)

Even though the General Data Protection Regulation (GDPR) primarily regulates the processing of personal data, there are overlaps with the tasks of an ISO. Companies that process large amounts of personal data are obliged to appoint a data protection officer. In practice, data protection officers and information security officers often work closely together, especially when it comes to protecting data from unauthorized access or loss.

4. ISO 27001 and certifications

Companies wishing to introduce or have certified an information security management system (ISMS) by ISO 27001 are faced with defining clear responsibilities for information security. Although the standard does not explicitly require the appointment of an ISO, in practice, it makes sense to entrust a central person with the management and monitoring of the ISMS. This person usually assumes a similar function to an information security officer and helps to ensure security standards.

5. Industry-specific requirements

Certain industries, such as the automotive industry, have additional security requirements that may require the appointment of an ISO. One example is the TISAX standard, which was developed especially for automotive suppliers to ensure information security for confidential data along the supply chain. In these cases, an information security officer helps to fulfill industry-specific security requirements and support certification.

When is it necessary to appoint an information security officer?

The appointment of an ISO is not a legal requirement for all companies. Nevertheless, legal requirements, such as the IT Security Act, the GDPR, or the implementation of ISO 27001, may require the appointment of an ISO. Industry-specific standards such as TISAX often require companies to appoint an information security officer. It’s crucial to carefully review your legal framework and industry-specific requirements to avoid legal consequences and ensure long-term information security.

What qualifications should an information security officer (ISO) have?

An information security officer has a key role in protecting company data and systems. To carry this responsibility effectively, they must have a wide range of skills and experience. The following qualifications are essential to fulfill the role of an ISO:

1. Professional qualifications of an ISO

Technical knowledge:

Information security officers need an in-depth understanding of IT security architectures, network security, encryption technologies, and firewalls. They should also be familiar with operating systems, server technologies, and cloud environments. This is necessary to identify vulnerabilities and take appropriate security measures.

Certifications:
To underpin its expertise, internationally recognized certificates in information security are particularly valuable. The most important of these include
  • ISO/IEC 27001 Lead Auditor or Lead Implementer: These certificates are proof of in-depth knowledge of implementing and monitoring an information security management system (ISMS).
  • CISM (Certified Information Security Manager): This certification focuses on the management side of information security and enables the ISO to develop security strategies.
  • CISSP (Certified Information Systems Security Professional): A globally recognized certification that covers technical and organizational aspects of information security.
  • CISA (Certified Information Systems Auditor):
  • This certification qualifies you to carry out audits in the field of information security.
Knowledge of legal regulations:
In addition to technical skills, a deep understanding of the legal framework is required. The information security officer must be fully familiar with data protection laws
such as the GDPR and know industry-specific security requirements.

2. Professional experience

Experience in information security:
Several years of practical experience in different IT or information security areas is essential. Ideally, the ISO has worked in different industries to gain a broad perspective on different security requirements.

Experience with ISMS:
An ISO should have demonstrable experience in implementing, monitoring, and maintaining an information security management system (ISMS). This is particularly important for companies aiming for or already have ISO 27001 certification.

Risk management:
One of the key tasks of an ISO is the ability to identify security risks, assess them, and develop appropriate mitigation measures. This involves proactively identifying threats and closing security gaps before they become problematic.

3. Soft Skills

Communication skills:
An ISO must be able to communicate complex technical issues in a way that is easy to understand. Communication between the IT department and management is critical to ensure that security measures are clearly understood and supported.

Analytical thinking:
To successfully fulfill the ISO role, it is essential to be able to systematically identify potential security vulnerabilities and develop strategies to address them. This requires a high degree of analytical thinking.

Sense of responsibility and integrity:
As the ISO is responsible for protecting sensitive data, a high level of accountability and integrity is essential. Companies must be able to trust that information security officers will act appropriately in crisis and always consider the company’s security.

4. Industry-specific knowledge

Certain industries must consider additional information security requirements. For example, ISOs in the automotive industry must be familiar with the requirements of TISAX. Special regulatory requirements play a central role in the financial industry. Therefore, an ISO should have in-depth knowledge of the relevant norms and standards in the respective industry.

5. Ongoing training

Since the threat situation in the information security field constantly changes, an ISO needs to participate in regular further training. They should always be informed about the latest developments in IT security in order to ensure the effectiveness of the measures implemented and to identify new risks at the earliest possible stage.

The combination of technical expertise, experience, and soft skills makes an information security officer an indispensable resource for any company. Especially in this age of growing digital threats, the ISO plays a central role in securing data and IT systems.

What advantages does an external information security officer (ISO) offer?

The decision to hire an external information security officer (ISO) comes with numerous benefits that can help organizations manage their information security effectively and efficiently. Here are the key benefits in detail:

1. Expert knowledge and experience

  • Specialist knowledge: Consultant ISOs often have deep expertise and extensive experience gained from working with various companies and industries. They are familiar with current threats and technologies.
  • Up-to-date: Through regular training and work on various projects, they are always aware of the latest regulations and best practices in the information security field.

2. Cost efficiency

  • Flexible duration of commitment: An external ISO can be hired at short notice as needed, which is often more cost-efficient compared to hiring an internal employee.
  • Avoidance of long-term personnel costs: Companies save on long-term personnel costs such as salary, social benefits, and training, as billing is usually based on projects or hours.

3. Independence and objectivity

  • Independent perspective: A consultant ISO brings an objective perspective, as they are not entangled in internal hierarchies or interests. This enables an unbiased assessment of the security situation.
  • Clear identification of vulnerabilities: This often allows vulnerabilities to be more clearly identified and remedied, increasing the overall organization’s security.

4. Scalability and flexibility

    • Customizable support: External ISO services can be flexibly adapted to the company’s current needs, whether for short-term projects or special requirements.
    • Scalability: Companies can scale the scope of services according to their risk profile and company size, ensuring they get the support they need.

5. Quick access to specialized knowledge

  • Industry-specific knowledge: A consultant ISO not only brings comprehensive expertise in information security but often also knowledge of specific industry requirements, such as TISAX for the automotive industry or the GDPR data protection guidelines.
  • Fast training: This expertise enables faster training and implementation of safety measures.

6. Focus on the core business

  • Relief of internal resources: By outsourcing information security tasks, the company can concentrate better on its core business while the external ISO takes care of security. This promotes efficiency and productivity.

7. Minimization of liability risks

  • Compliance with legal requirements: A professional external ISO ensures that the company complies with all legal and regulatory requirements. This significantly reduces the risk of fines or liability claims.
  • Risk management: The consultant ISO helps identify and manage potential risks at an early stage, which protects the company better overall.

Working with an external information security officer offers companies a practical, flexible, and effective solution for ensuring information security without burdening internal resources. In this way, companies can ensure that they are optimally prepared for the challenges in the information security field.

Our many years of experience as information security officers, especially for medium-sized businesses, make us the ideal partner for you.

We address the specific requirements and challenges for your industry and can offer you tailor-made solutions that are both practical and scalable. Our team consists of ISO 27001 Lead Auditors who have successfully led numerous companies to ISMS certification.

About the Author

ISO 27001 certification experience

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

What are the responsibilities of an Information Security Officer (ISO)? Read More »

ISO 27001 certification experience

Information security management system – ISMS according to ISO 27001

The information security management system (ISMS) following ISO 27001 is a management system that focuses on the security of information in a company. Companies should implement an ISO 27001-certified Information Security Management System (ISMS) to ensure information confidentiality, integrity, and availability.

As part of the ISMS, risks and vulnerabilities are identified to implement appropriate information security controls. ISO 27001 certification allows companies to demonstrate the security of their IT systems to their customers and partners.

Table of contents:

  • What is an ISMS information security management system?
  • What are the benefits of an ISMS following ISO 27001?
  • What are the components of an information security management system?
  • ISMS – Reducing IT risks and systematically managing information security
  • How is the ISMS certified according to ISO 27001?

What is an ISMS information security management system?

An ISMS is a management system that aims to ensure information security in a company. It includes implementing measures to ensure IT security, documenting processes and guidelines, and complying with the requirements of ISO 27001 certification.

An ISMS following ISO 27001 is part of IT baseline protection and comprises the establishment and development of a system that covers the area of information security. The ISMS implementation should also help organizations meet the requirements of ISO standards such as ISO 27001 or IEC 27002 and successfully pass audits. By implementing an ISO 27001-certified ISMS, companies demonstrate their commitment to sensitive information and data security.

What are the benefits of an ISMS following ISO 27001?

From our project experience, an ISMS following ISO 27001 offers numerous advantages for companies.

  1. Confidentiality, integrity, and availability of information:
    • An ISMS ensures that company information is optimized and managed more securely.
    • It protects against security incidents, reputational damage, and data loss.
  2. Compliance and data protection:
    • Ensuring compliance with regulations such as the GDPR (General Data Protection Regulation) and the ISO 27001 standard
    • This enables companies to meet legal requirements and gain the trust of customers and business partners.
  3. Risk management:
    • An ISMS is used to identify, assess, and monitor risks.
    • It enables systematic management of information security risks.
  4. Protection against cyber attacks:
    • Data and systems are protected against cyber attacks. It is part of basic IT protection.
    • It minimizes the effects of faults and security breaches.
  5. Corporate growth and competitiveness:
    • Companies with a well-implemented ISMS and certificate are more attractive to customers.
    • It supports secure corporate growth and improves competitiveness.
  6. Trust and reputation:
    • An ISMS gains the trust of customers and business partners.
    • It protects the company’s reputation.

What are the components of an information security management system?

These are the components required to certify an information security management system (ISMS) following ISO 27001:

  1. Information security policy
    Defines the overarching objectives and framework conditions for information security in the company.
  2.  Risk management process
    Identification, assessment, and treatment of information security risks.
  3. Guidelines and procedures
    Detailed documentation of security guidelines and procedures for implementing the information security policy.
  4. Asset management
    Identification and management of all information-relevant assets.
  5. Access controls
    Measures to ensure that only authorized persons have access to information and information systems.
  6. Training and awareness-raising
    Regular training and programs to raise employee awareness of information security.
  7. Incident management
    Processes for detecting, reporting, and handling security incidents.
  8. Continuous improvement
    Regular review and improvement of the ISMS through internal assessments and management reviews.

These components are essential for establishing and operating an effective and certifiable ISMS.

Here you can find out what is involved in an information security management system (ISMS) implementation.

Additional useful components of an ISMS:

    1. Business continuity management
      Strategies and plans to maintain business operations if disruptions or security incidents occur.
    2. Supplier Management
      Security requirements and assessments for third-party providers and suppliers.
    3. Compliance management
      Ensuring compliance with all relevant legal, regulatory, and contractual requirements.
    4. Physical security
      Measures to protect physical locations and devices from unauthorized access and damage.
    5. Cryptographic measures
      Using encryption and other cryptographic methods to protect information.
    6. Technical security controls
      Using firewalls, intrusion detection systems (IDS), antivirus software, and other technical security solutions.
    7. Document and record management
    Management and protection of information security documents and records

ISMS - Reducing IT risks and systematically managing information security

The Information Security Management System ISMS ISO 27001 is a systematic approach to managing sensitive company information and ensuring its security. By establishing an ISMS, companies can effectively identify, assess, and manage a wide IT risks range. We have listed the main IT risks that can be managed through an ISMS and added an explanation of how the system works:

The main IT risks that an ISMS can manage and the corresponding measures:

  1. Data loss and data corruption
    Implementation of backups, access controls, and encryption techniques.
  2. Unauthorized access
    Using strong authentication mechanisms, regular review of access rights, and security monitoring.
  3. Malware and cyber attacks
    Using anti-malware software, firewalls, and intrusion detection systems (IDS).
  4. Phishing and social engineering
    Awareness-raising and employee training, implementation of e-mail security protocols, and anti-phishing tools.
  5. Vulnerability management in the software
    Regular security updates, patch management, security assessments of the software, and pentesting.
  6. System failures and technical malfunctions
    Implementation of redundancy, failure protection, and disaster recovery plans.
  7. Compliance violations
    Compliance with legal and regulatory requirements through continuous monitoring and adaptation of security measures.
  8. Insider threats
    Establish clear security policies, monitor employee activities, and segregate duties.

How do ISMS components work to reduce risk?

  1. Risk assessment and management:
  • Identification of risks: By systematically analyzing and evaluating all information resources and their threats.
  • Assessment of the risks: Determining the likelihood and impact of potential security incidents.
  • Treatment of risksSelecting and implementing suitable risk mitigation, avoidance, or acceptance measures.
  1. Development of security guidelines:
  • Policies and procedures: Create detailed documentation on security policies and procedures to ensure consistent and comprehensive security practices.
  • Awareness-raising and training: Regular training and awareness-raising programs for employees to promote awareness and competence in dealing with security risks.
  1. Monitoring and assessment:
  • Continuous monitoring: Regelmäßige Überprüfung der Sicherheitsmaßnahmen und -prozesse, um sicherzustellen, dass sie effektiv und aktuell sind.
  • Internal and external audits: Conduct audits to verify ISMS compliance with ISO 27001 and other relevant standards.
  1. Continuous improvement:
  • Management reviews: Regular management review of the ISMS to assess its performance and efficiency.
  • Corrective measures: Implementing improvements and corrective measures based on the results of audits, monitoring, and assessments.

An ISMS offers companies a structured and systematic method for managing their information security risks. By implementing an ISMS, companies can reduce their IT risks and ensure their information’s confidentiality, integrity, and availability. This leads to increased trust among customers and partners and compliance with legal and regulatory requirements.

How is the ISMS certified according to ISO 27001?

ISO 27001 certification of an ISMS is carried out in three steps:

  1. Internal audit
  • Preparation and planning: The company prepares internal audits by drawing up an audit plan and identifying the relevant areas and processes.
  • Implementation: Internal auditors or external consultants systematically check the ISMS for conformity with the ISO 27001 requirements. They identify vulnerabilities and potential for improvement.
  • Reporting: The results are documented, and corrective measures for identified deficiencies are planned and implemented.
  1. External audit by an authorized auditor for certification
  • Document review: An external auditor reviews the company’s ISMS documentation to ensure all required policies, procedures, and records are in place and meet the ISO 27001 standard.
  • On-site audit: The auditor visits the company to check the practical implementation of the ISMS. This includes interviews with employees, inspections of processes and systems, and a review of the corrective measures from the internal audits.
  • Certification decision: Once the on-site audit has been completed successfully, the auditor compiles a report and decides whether the company will receive ISO 27001 certification. If the outcome is successful, the certificate is issued.
  1. Continuous monitoring
  • Follow-up audits: After certification, the external auditor conducts follow-up audits at regular intervals to ensure that the ISMS continues to conform and function effectively.
  • Continuous improvement: The company must continuously monitor, evaluate, and improve the ISMS. This includes regular assessments, management reviews, and taking action to address new risks and opportunities for improvement.
  • Re-certification: The company must undergo a comprehensive re-certification audit to renew the ISO 27001 certification every three years.

These steps ensure the ISMS is initially compliant, remains effective over time, and is continuously improved.

About the Author

ISO 27001 certification experience

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

Information security management system – ISMS according to ISO 27001 Read More »

ISO 27001 certification experience

VDA ISA 6 – The Most Important Changes in the Catalog

Templates for TISAX 

Information security in the automotive industry is about to undergo a significant change as TISAX® has brought a new level of security to the industry. For years, TISAX® has served as an important standard for information and cybersecurity in the automotive industry. Now, the German Association of the Automotive Industry (VDA) has updated the catalog, and from 1 April 2024, version 6.0 will replace version 5.1.

This new VDA questionnaire expands the TISAX requirements and increases the level of information security, especially in the areas of incident management, crisis management, business continuity, and backup/restore, as well as the complete revised data protection catalog.

As information security experts at 360 Digital Transformation GmbH, we would like to offer you comprehensive guidance on how you can efficiently manage this transition and how you can upgrade your existing ISMS to the new version 6 according to TISAX 5.1 or start directly with the implementation of an ISMS (Information Security Management System) according to TISAX VDA 6.0.

What's new in the VDA ISA catalog version 6?

The new revision of the VDA 6.0 catalog includes significant changes and enhancements that affect the scope and specific controls.

New controls and requirements

There are new controls, requirements, and additions to wording. The new topics have an extended focus on IOT/OT, including IT systems and IT services, software management, incident and crisis management, security incident reporting, security incident management, handling crises, IT service continuity planning, BCM, and backup and recovery.

Updating the "Data protection" module

The module has been completely revised and now contains 12 controls that consider the requirements of the GDPR and other data protection regulations.

New labelling

With the introduction of VDA 6.0, the previous TISAX® labels “Info High” and “Info Very High” were split to present the safety levels more clearly and specifically. The new labels are:

  • High Availability: For systems where availability is of crucial importance.
  • Confidential: For systems that contain confidential information.
  • Very High Availability: For systems that require very high availability.
  • Strictly Confidential: For systems with strictly confidential information.

This new structure enables a more precise categorization of security requirements and helps companies implement their information security measures in a better-targeted way.

When will VDA ISA catalog 6.0 become valid?

The official transition to VDA 6.0 begins on April 1, 2024. Companies that have already completed an Audit following VDA 5.1 must switch to new version 6.0 to keep their TISAX label.

What is eliminated with the VDA ISA catalog 6.0?

With the introduction of VDA 6.0, some existing controls from VDA 5.1 were removed or replaced. Particularly noteworthy is the deletion of control 3.1.2, covered by the new controls 1.6.3, 5.2.8, and 5.2.9. The ISA 4 compatibility tab has also been removed to create space for updated and more relevant requirements.

Facts and numbers for version 6.0 compared to 5.1

For a clearer picture of the changes, here are some key figures:

  • VDA 5.1: 41 controls, 271 requirements (Info High/AL2), 5 requirements (Info Very High/AL3).
  • VDA 6.0: 45 controls, 297 requirements (Info High/AL2), 17 requirements (Info Very High/AL3).

Here, you can see in terms of numbers that the AL2 requirements (Info High) have increased by about 10%. AL3 requirements (Info Very High) have been increased quite a bit, but it now depends on which label (Confidentiality, Availability, or both) it is.

Overall, the number of requirements has increased by around 12%. However, this does not mean that the effort required for an ISMS by VDA 6.0 is 12% higher. We estimate 20-25% additional effort for implementation, depending on the complexity of the extended requirements.

New controls and requirements for revision 6.0 in detail

The new and revised controls in VDA 6.0 affect numerous areas:

  • Section 1:
    • New and revised requirements for software release and incident management
    • 1.6 “Incident and crisis management”: Renamed and expanded to create a clear structure for managing security incidents and crises.
    • New control:
    • 1.3.4 “Software approval”: This new control ensures that only approved software is used, including software release, licensing, and patch management.
    • 1.6.2 “Management of security incidents”: New control for an orderly and timely response to security incidents.
    • 1.6.3 “Dealing with crises”: This control replaces the previous control 3.1.2 and aims to prepare organizations for crises.
  • Section 3:
    • This chapter has been renamed to “Physical Security”, mainly due to the deletion of “Control”. 3.1.2.
  • Section 4:
    • Extensions and additional requirements for access controls (4.1.1, 4.1.2, 4.1.3, 4.2.1).
  • Section 5:
    •  5.2.8 “IT service continuity planning”: Focuses on IT service continuity planning, including redundancy and recovery of key systems.
    • 5.2.9 “Backup and recovery”: Ensures organizations are prepared to recover data and systems after security incidents.
    • New and revised requirements for IT services and IT audits (5.1.1, 5.1.2, 5.2.6, 5.2.7, 5.3.1)

New control:

  • Data protection module:
    • 9.1.1 (Data Protection Policies)
    • 9.2.1 (Organization of Data Protection)
    • 9.3.1 (Processing directory)
    • 9.4.1 (Data protection impact assessment)
    • 9.5.1-9.5.2-9.5.3 (Data transfers)
    • 9.6.1-9.6.2 (Handling requests and incidents)
    • 9.7.1-9.7.2 (Human Resources)
    • 9.8.1 (Instructions)

What does the transition process look like for existing companies in the automotive industry?

The transition from VDA 5.1 to VDA 6.0 requires careful planning and implementation. Here are the steps you should consider:

  1. Conduct a GAP analysis: Identify the differences between your current implementation and the new requirements of VDA 6.0. That will help you to detect gaps in your existing ISMS.
  2. Updating the documentation: Adapt your safety documentation to the new controls and requirements.
  3. Implement the new controls: Implement the new controls and ensure that all necessary actions are taken.
  4. Training and awareness: Ensure that your team understands the changes and the new requirements.
  5. Internal audits: Conduct internal audits to verify the effectiveness of the new controls.
  6. Management review: Conduct a management review to ensure that management understands and supports the customized ISMS.
  7. TISAX audit: Finally, the adapted ISMS must be audited by an approved TISAX audit company.

Direct implementation of an ISMS for information security according to TISAX® with VDA ISA 6

Direct implementation of VDA 6.0 offers an excellent opportunity to meet the latest requirements from the start if you have not yet implemented an ISMS. Here is an overview of the process:

  1. GAP analysis: Determine the current status of your company
  2. Initial planning: Plan measures based on the GAP analysis for implementing the ISMS.
  3. Risk assessment: Conduct a detailed risk assessment to identify the specific security risks your organization is exposed to.
  4. Security policy development: Create comprehensive security policies and procedures that meet the requirements of VDA 6.0.
  5. Implement the controls: Implement the necessary technical and organizational controls to mitigate the identified risks.
  6. Training and awareness: Train your employees regularly on the new security guidelines and procedures.
  7. Monitoring and assessment: Continuously monitor the effectiveness of implemented controls and conduct regular assessments to identify opportunities for improvement.
  8. Preparation for the TISAX assessment: Ensure that all required documents and evidence for the TISAX assessment are in place.
Note: The VDA has already published the successor catalogue, VDA ISA 2027 – applicable to assessments commissioned from 2027; the binding date is set by ENX. Read the key changes in VDA ISA 2027 – The Most Important Changes.

Support from 360 Digital Transformation GmbH

We offer comprehensive support to guide your company through the transition to VDA 6.0. Our approach includes:

  1. GAP analysis: We identify the gaps between your current security situation and the ISA catalog version 6 requirements.
  2. Consulting and implementation: Our experts support you in implementing the new controls and requirements.
  3. Training courses: We offer customized training programs in German or English to prepare your team for the new requirements.
  4. Internal audits and preparation for the TISAX assessment: We help you to carry out internal audits and prepare optimally for the TISAX assessment.
  5. Ongoing support: Our team will still support you after the transition to ensure that your ISMS meets the latest standards and is improving constantly.

What is the outcome for TISAX® users?

The transition from VDA 5.1 to VDA 6.0 entails numerous changes and new requirements that companies should implement carefully. With our extensive expertise and comprehensive services, we support you in making this transition smoothly and successfully implementing your information security management system as per TISAX®.

About the Author

ISO 27001 certification experience

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX® consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

TISAX® is a registered trademark of the ENX Association. 360 Digitale Transformation has no business relationship with ENX. The mention of the TISAX® trademark does not constitute any statement by the trademark owner regarding the suitability of the services advertised here. TISAX® assessments for obtaining labels are carried out only by the audit providers listed on the ENX website.

VDA ISA 6 – The Most Important Changes in the Catalog Read More »

ISO 27001 certification experience

ISO 27001 Certification: Explaining costs, process, and timeline

What are the costs of ISO 27001 certification for small businesses?

From our perspective, ISO 27001 certification is essential for ensuring compliance with internationally accepted information security standards.

Determining the costs of ISO 27001 certification begins with a gap analysis to prepare for the subsequent steps. You also need to consider targeted staff training, internal resource planning, and internal audit performance.

Implementing and auditing an Information Security Management System (ISMS) has costs. External auditors from the certification body perform the certification audit to verify compliance with the ISO 27001 standards.

The costs for implementing and certifying ISO 27001 vary depending on the company’s size and complexity and a range of other factors, which we will discuss below.

The costs of complying with ISO 27001 certification depend on the size of the company, the number of employees, and the company’s location. Companies must consider the costs of introducing the information security management system as well as the ongoing costs of monitoring and inspections by external auditors. To optimize certification costs, we recommend relying on the expertise of experienced consultants to implement the ISO 27001 standards efficiently and economically.

What are the internal and external components of the costs of ISO 27001 certification?

We have listed all phases and the associated costs for you so that you have maximum transparency:

 1. Assessment of the current security situation:

      • External audit costs by security experts or internal resources who spend time and resources assessing current security practices.

    2. Creation of an ISMS (Information Security Management System):

        • The costs for developing and implementing a customized ISMS include adapting the guidelines, procedures, and processes.
        • Possible expenses for the ISMS software or tools to manage the security measures.

      3. Employee Training:

          • Costs for training and training materials to improve employee security awareness.
          • The time required for internal trainers or external training providers.

        4. Certification fees:

            • Fees are charged by the accredited body for conducting the certification review.
            • The amount of the fees may vary depending on the size and type of company and the scope of the certification.
            • The exact certification fees vary depending on the certification body chosen, the scope of the certification, and other specific requirements.
            • Costs for the ISMS documentation review and processes by the certification body.
            • Any additional expenses for revisions or corrections.

          5. Required internal resource planning and how you can reduce it with external consulting:

          Coordinate the time and staff resources required for the certification process and following ISMS management. Take these points into account when planning resources:

              • Consulting on ISMS development:

                An external consultant can help develop and implement a customized ISMS that meets the company’s specific demands.

              • Support with documentation:

                A consultant can help create and update the necessary documentation and guidelines for the ISMS.

              • Training and awareness-raising:

                A consultancy can help implement training and awareness programs to enhance employees’ security awareness within the company

              • Certification preparation:

                Guidance in preparing for the ISO 27001 certification audit, including internal audits, mock audits, and identifying vulnerabilities to optimize the certification cost.

              • Technical expertise:
                Access to specialist knowledge and internationally recognized best practices from other information security projects to ensure the ISMS complies with current standards and requirements.

            6. Technological investments

            Procurement and implementation of security technologies such as firewalls, encryption solutions, etc.

            7. Ongoing expenses

                • Costs for regular internal audits and reviews of the ISMS
                • Regular training for employees to maintain security awareness

              What specific costs do small companies have to expect for external consulting?

              Based on our experience, we have summarized the available consulting options for the relevant price range.

               The costs can be divided into three parts, which are explained in detail:

                  1. GAP analysis: A GAP analysis is like a doctor’s X-ray. GAP analysis presents the current situation and what needs to be done to achieve ISO 27001 certification. It is based on the ISO 27001 roadmap. It can be carried out as a one-day workshop and, based on experience, costs between €2,000 and €5,000.
                  2. Preparation, self-assessment, technical and physical security analysis, and ISMS structure: This is the most labor-intensive part of the ISO 27001 project. Due to the different efforts involved, this part ranges from €6,000 to €15,000.
                  3. Establishment of guidelines, processes, necessary documentation, and audit support: This is the last part of your ISO 27001 roadmap and costs between €7,000 and €14,000.

                In general, the budget requirement is between €15,000 – € 35,000. If you have a team of two, the consultancy pays for itself by saving a week’s work, which is the case in most situations.

                The project duration can be between 3 and 9 months. Please also bear in mind that you will need to budget for additional costs for the independent auditing company.

                For further information, please make an appointment with us.

                 

                Frequently asked questions about costs for ISO 27001 certification

                What are the requirements for obtaining an ISO 27001 certificate?

                Our experience from more than 30 projects shows that companies need to fulfill several requirements to obtain an ISO 27001 certificate. This includes setting up and implementing an information security management system that meets the ISO 27001 requirements. Conducting a risk assessment, implementing security controls, and documenting all security measures are also required. In addition, companies must conduct regular internal audits and undergo an external certification audit to ensure that the implementation of an ISMS complies with ISO 27001 standards and ensures the integrity and availability of information.

                How long is an ISO 27001 certification valid?

                The validity period of an ISO 27001 certification is always 3 years. During this period, the annual follow-up audits take place.

                What are the costs of the ongoing operation of the information security management system?

                    1. Hardware and software costs: Acquiring and maintaining IT infrastructure and security software.
                    2. Employee expenses: Compensation for security experts who manage and monitor the ISMS.
                    3. Updates and changes: Regular updates of security solutions and systems.
                    4. Protective measures: Expenses for monitoring, penetration testing, and security training.

                  About the Author

                  ISO 27001 certification experience

                  Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

                  ISO 27001 Certification: Explaining costs, process, and timeline Read More »

                  ISO 27001 certification experience

                  ISO 27001 Requirements for Certification – A Guide for Companies

                  ISO 27001 certification experience

                  Data is a company’s most valuable resource in today’s digital era. Therefore, securing that data is extremely important. This internationally recognized standard defines the ISO 27001 requirements. Companies are supported in implementing and maintaining a robust information security management system (ISMS).

                  Our guide, based on the experience of more than 50 projects, provides a comprehensive insight into the requirements of ISO 27001 certification. It is an indispensable resource for organizations that want to update their information security practices and seek certification.

                  This guide explains the key steps that companies need to take to achieve ISO 27001 certification, starting with the benefits and continuing through the continuous improvement of an ISMS.

                  Discover the opportunities for your company in information security and how ISO 27001 compliance can give you a competitive advantage.

                  What are the advantages of ISO 27001 certification?

                  Here is an overview of the advantages of implementing ISO 27001 for companies based on our customer projects:

                  1. Improved security level: ISO 27001 provides a structured framework for identifying, assessing, and addressing information security risks. By identifying and addressing potential vulnerabilities, the company’s level of security improves.
                  2. Trustworthiness and credibility: ISO 27001 certification is an internationally recognized label for compliance with high-security standards. Through certification, a company can build trust with customers, partners, and other stakeholders and strengthen its credibility.
                  3. Meeting customer requirements: Many companies increasingly demand ISO 27001 certification from their suppliers. By implementing the standard, companies can meet their customers’ requirements and thus gain a competitive advantage.
                  4. Legal and regulatory compliance: ISO 27001 helps companies comply with legal and regulatory requirements in the data protection and information security field. This helps to avoid fines and legal consequences that can result from non-compliance.
                  5. Increased efficiency: Companies can improve the efficiency of their processes by implementing a systematic information security management system (ISMS) following ISO 27001. This includes optimizing security measures, resource usage, and minimizing security incidents.
                  6. Risk mitigation: ISO 27001 assists organizations in proactively identifying and assessing risks related to information security. Adapting security controls that comply with the standard helps companies manage effectively and minimize potential threats and vulnerabilities.
                  7. Continuous improvement: The standard promotes a culture of continuous improvement by encouraging organizations to review regularly and adapt their information security practices. In this way, companies can continuously adapt to the changing threats and requirements and improve their level of security.

                  Learn more about the ISO 27001 standard requirements

                  Overview of the ISO 27001 requirements

                  ISO 27001 is an internationally recognized standard that defines requirements for establishing, implementing, maintaining, and continuously improving an information security management system (ISMS). This overview provides a structured and easy-to-understand presentation of the ISO 27001 requirements. Each section and requirement is illustrated with practical examples to make the concepts more tangible and facilitate implementation within the company.

                  1. Applicability and context in the company - The 27001 requirements at a glance

                  1.1. The organization and its context: understanding the internal and external landscape

                  • Identify internal and external factors that may affect the organization’s ability to achieve the intended outcomes of the information security management system (ISMS).
                  • Examples: Setting up a corporate strategy, researching market conditions, and auditing legal requirements.

                  1.2. Needs and expectations of the interested parties

                  • Determine the requirements and expectations of relevant stakeholders (e.g. customers, legislators, employees).
                  • Examples: Systematic recording of customer requirements and legal regulations.

                  1.3. Defining the scope of the ISMS

                  • Define which parts of the organization and which information resources the ISMS covers.
                  • Examples: These can include business processes, technologies, or geographical locations.

                  2. Leadership - Trendsetting Manager

                  2.1. Management commitment

                  • Ensure that top management supports the implementation of the ISMS and takes responsibility for it.
                  • Examples: By providing resources and promoting a safety culture.

                  2.2. Information security policy

                  • Develop and communicate a security policy that defines the organization’s information security objectives and commitment.
                  • Examples: Establish corporate information security policies and make public security declarations.

                  2.3. Roles, responsibilities, and powers

                  • Define and communicate clear roles and responsibilities for information security.
                  • Examples: Appointing an information security officer (ISO) in the company and setting up an incident response team.

                  3. Planning - Anticipating challenges

                  3.1. Risk management

                  • Identify and assess information security risks and plan measures to address these risks.
                  • Examples: Carrying out regular risk analyses with the help of risk management plans.

                  3.2. Information security objectives and target achievement planning

                    • Defining measurable safety targets and planning measures to achieve these targets.
                    • Examples: Targeted reduction of security incidents by increasing the employee awareness rate and conducting regular training.

                  3.3. Risk treatment measures

                  • Develop measures to address identified risks, including acceptance, reduction, transfer, or avoidance.
                  • Examples: Implementing technical controls and taking out insurance for existing security gaps.

                  4. Support - Strengthening the security infrastructure

                  4.1. Resource management

                  • Ensure sufficient resources (time, money, personnel) are provided for the ISMS implementation and maintenance.
                  • Examples: Clear budget planning and staff training in preparation for ISO 27001 certification.

                  4.2. Competence and training

                  • Identify necessary skills and provide training to develop these skills.
                  • Examples: Information security training and the introduction of employee certification programs.

                  4.3. Awareness and communication

                  • Promote awareness of information security and establish effective communication processes.
                  • Examples: Awareness campaigns for dealing with risks and opportunities and setting up internal communication guidelines.

                  4.4. Documented information

                  • Create and maintain documented information to support the ISMS.
                  • Examples: Writing down clear security guidelines, introducing systematic process documentation, and creating incident records.

                  5. Operation - Effective implementation of information security

                  5.1. Operational planning and control

                  • Plan, implement, and control processes to meet information security requirements.
                  • Examples: Require the development of operational plans and continuous process controls.

                  5.2. Risk treatment in the company

                  • Implement risk treatment measures and ensure that they work as planned.
                  • Example: Have technical checks carried out by the IT department.

                  5.3. Security Incident Management

                  • Identify and respond to information security incidents and ensure the implementation of measures.
                  • Examples: Have incident response plans drawn up by the security officer (ISO) and establish clear escalation processes.

                  5.4. Emergency management and recovery

                  • Develop and implement contingency and disaster recovery plans.
                  • Examples: Have emergency plans and recovery measures defined by the safety officer.

                  6. Performance assessment - Measurement and assessment of progress in the fulfillment of ISO standards

                  6.1. Monitoring and assessment

                  • Monitor and assess the performance of the ISMS using defined key figures.
                  • Examples: Safety metrics can be used to create regular monitoring reports.

                  6.2. Internal audits

                  • Plan and conduct regular internal assessments to check the effectiveness of the ISMS.
                  • Examples: Audit plans and audit reports are the basis for ongoing internal assessments.

                  6.3. Management reviews

                  • Management regularly evaluates the suitability and effectiveness of the ISMS using ISMS KPIs that reflect the effectiveness of the information security measures. For example, the effectiveness of employee awareness measures, the number of systems audited or systems in automated patching, etc.
                  • Examples: Creating clear, precise meeting minutes that record important discussion points, decisions, and responsibilities. Establish meaningful metrics to measure ISMS performance.

                  7. ISO 27001 certification of the company with the final audit

                    • Procedure for obtaining and maintaining ISO 27001 certification by an external auditor. With the certification, you also receive the corresponding proof for your company.
                    • The process for obtaining and maintaining ISO 27001 certification comprises several important steps:
                        • Carrying out a gap analysis
                        • Implementation of necessary measures
                        • Internal assessments with the support of our consultants
                        • Formal certification by an external auditor.
                    • The certification confirms that the ISMS meets the requirements of ISO 27001 and has been effectively implemented.
                    • Regular monitoring audits ensure that compliance is maintained and the system is improved continually.
                    • Examples: Internal audits, external audits, and the associated certification processes.

                    You can also read our article on the costs of ISO 27001 certification.

                  8. Continuous development after ISO 27001 certification

                  8.1. Corrective measures

                  • Take measures to eliminate the causes of non-conformities to prevent their recurrence.
                  • Examples: Carrying out a root cause analysis with subsequent corrective measures.

                  8.2. Ongoing improvements

                  • Identify and implement improvement opportunities for the ISMS.
                  • Examples: Setting up improvement projects with previously created best practice analyses.

                  Additional aspects of the organization's requirements

                  1. Information security controls

                  • Implement specific technical and organizational controls to secure information.
                  • Examples: Introduction of access controls, encryption, and network security controls.

                  2. Legal and regulatory requirements

                  • Ensure that the ISMS fulfills all relevant legal and regulatory requirements.
                  • Examples: Compliance with data protection laws and industry-specific regulations.

                  ISO 27001 controls and how they relate to requirements

                  ISO 27001 controls are specific measures or security controls implemented to meet the standard requirements. They are described in Annex A of ISO 27001 and serve as the basis for dealing with identified risks as part of an information security management system (ISMS).

                  Context:

                  • The requirements of ISO 27001 (chapters 4 to 10) define the structural and procedural framework for how an ISMS must be set up and operated. The controls (Annex A) are concrete measures for risk management that are implemented within this framework in order to address specific risks and ensure information security. The Statement of Applicability (SoA) then documents which specific security controls from Appendix A are implemented within this defined scope and provides reasons for selecting or excluding each control.

                  ISO 27001 Controls identify, assess, and manage information risks

                  ISO 27001 Controls are concrete security measures that an organization can implement to manage information security risks and meet the requirements of ISO 27001. These measures cover various areas and explain their applicability:

                  • Policies and organization: Develop and maintain clear information security policies and define responsibilities to support the organization’s security objectives.
                  • Staff: All employees should receive appropriate training and awareness programs to promote the understanding and importance of information security. Training should cover specific threats and protective measures and be updated regularly.
                  • Assets: Effectively manage and protect information assets such as data, hardware, and software. Measures include classifying and labeling information according to sensitivity and criticality, regular backups, access controls, and physical security measures to protect against loss, theft, or damage.
                  • Access controls: Regulate who has access to which information and systems and protect access with passwords, authorizations, and other security mechanisms.
                  • Cryptography: Use encryption and key management to protect information from unauthorized access.
                  • Physical security: Secure physical facilities such as offices and server rooms against unauthorized access and environmental influences.
                  • Operational security: Plan and control operational processes to ensure that IT systems are operated securely and are protected against malware and other threats.
                  • Communication security: Protect networks and the transmission of information so that data arrives securely and unaltered.
                  • System development and maintenance: Integrate security requirements into the entire life cycle of IT systems, from development to implementation and maintenance.
                  • Supplier management: Manage security aspects in relationships with suppliers to ensure that they also comply with the security requirements of the ISO 27001 standard.
                  • Incident management: Detect, report, and manage security incidents effectively and consistently to minimize damage and learn from incidents.
                  • Continuity management: Plan and implement measures to maintain information security even during disruptions.
                   

                  Overall, these controls and the measures listed for dealing with risks help to identify, assess, and handle information risks. Therefore, they form the backbone of a solid information security management system. These controls ensure that information security requirements are addressed systematically and comprehensively following the ISO 27001 standard.

                   

                  About the Author

                  ISO 27001 certification experience

                  Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

                  ISO 27001 Requirements for Certification – A Guide for Companies Read More »

                  360 Digitale Transformation
                  Privacy Overview

                  This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.