Information Security is Sexy!

Information security is sexy, do you believe us? In today’s world, even the smallest companies often generate large volumes of data. Data takes many forms, but can always be simplified to a form of information – a client list, a Word document containing business goals for the next quarter, passwords for your online banking system, et cetera. This data is all immensely valuable to not only you, but also potentially to criminals, business competitors, and other adversaries. So, what can you do to protect that data? This is where information security becomes relevant. An excellent first step in information security is to form an Information Security Management System. 

What is an Information Security Management System?

An Information Security Management System (ISMS) is a group of policies designed to help your organization streamline the management of threats to your data and physical assets. These policies are concerned with protecting the concept of the CIA Triad within your organization: Confidentiality, Integrity, and Availability. These three properties are described as:

Confidentiality: Information is only available to those who are authorized to access it.
Integrity: Information is protected from being modified in an unauthorized or undetected way.
Availability: Information can be accessed when it is needed.

A good ISMS will guide an organization on how to protect the Confidentiality and Integrity of its data while ensuring that the protections in place will not get in the way of the data’s Availability for authorized users. Additionally, the ISMS should detail how the organization will train users to follow these policies, and how to respond to threats against information security.

Implementing an ISMS

Creating an ISMS for an organization can be a daunting task; there is a lot to do and will involve a lot of effort across the entire organization. Most importantly, the upper-level management of the organization must recognize the necessity of such programs and be willing to support the implementation and continue enforcement of the policy. Once the organization is committed, the next steps would generally involve picking a standard to follow, determining the scope of the ISMS, performing a risk analysis, writing policies built around the results of this analysis, and making the ISMS official policy.

Choosing an ISMS standard

There are many standards available to follow that will guide an organization to a functional ISMS, often based on the unique laws and industry requirements of the organization. These standards include, but are not limited to, the ISO/IEC 27000 series (developed by the International Organization for Standardization), NIST 800-53 (developed by the United States Department of Commerce), COBIT (developed by the Information Systems Audit and Control Association), and O-ISM3 (developed by The Open Group). Each of these standards has benefits and drawbacks; it is up to each organization to determine which system is the best fit for them.

In Conclusion, Information Security is Sexy because it helps protect your data and ultimately your business. Planning appropriately with a solid ISMS could be what saves your company.

In our next post, we will discuss the idea of creating scope for your ISMS.

Browse all insights