ISO 27001
Who it's for
Organizations required to comply with Taiwan's Cyber Security Management Act or client/tender requirements, or that want to manage information-security risk systematically.
Problems we solve
Fragmented security practices, lack of risk management, and difficulty proving security capability to customers.
Benefits
Establish an ISMS and pass third-party certification, reducing security-incident and compliance risk and building customer trust.
What is information security? The ISO 27001 definition
Per ISO 27000 Clause 2.33, information security means preserving the confidentiality, integrity and availability of information (other attributes such as authenticity, accountability, non-repudiation and reliability may also be involved). In short: confidentiality means those who should not see information cannot; integrity means data is complete and unaltered; availability means information can be used when needed.
Basic elements of information security management
The basic elements can be grouped into software, hardware, people, network and environmental facilities.
Software
- Function first by design: if security is not built into functional requirements from the start, designers tend not to consider it, leaving only basic security features.
- Security added only recently: historically, security was addressed only after incidents occurred; e.g., secure data transmission was considered only after data was intercepted.
- OS vulnerabilities always exist: operating systems prioritize hardware operation and convenience — and convenience often means insecurity; the question is only whether flaws are discovered and exploited.
- Application life cycle affects security: legacy systems kept in use to support special applications cannot guarantee a given level of security.
Hardware
- Cost and firmware: cost pressures leave hardware security under-considered; firmware sits between hardware and software, and a flaw in any of the three can be exploited.
- Mobile devices: great gains in performance and capacity bring convenience — and security concerns.
- IoT devices: simple designs using only firmware and lightweight software create corresponding security issues.
- Industrial control: control-type devices' security issues often affect the equipment they control (e.g. metro train control).
People
- Hackers: once driven by fame, now largely by profit; techniques evolve with technology and trend toward "Hacking as a Service," changing how likelihood is assessed in risk analysis.
- Malicious insiders: the hardest factor to analyze; monitoring and evidence retention are needed, especially where highly sensitive information is handled.
- Negligent employees: without malice they can still cause breaches; appropriate training and agreements help.
- Visitors / external parties: access to internal resources should be classified and controlled with clear rules.
Overall, people are the most complex and most important link — behavior cannot be fully controlled by rules alone.
Network & communications
- Original design: networks were built to exchange data, not with security in mind; transmission security is now a growing concern.
- Wireless: the best solution for mobile devices, but requires careful controls.
- VPN: widely used, but does not guarantee security; misuse can increase risk.
- Segmentation: government guidance recommends separating networks (external firewall; internal DMZ, servers, users) to limit cross-zone exposure.
Environmental facilities
- Physical area security: control and log access to rooms holding key equipment and data.
- BYOD: increasingly portable, high-capacity devices have a critical impact on environmental security.
- Critical infrastructure: network, power and water affect availability — power stability in particular should be planned for early.
Threats
A threat is an external event or condition that can damage the basic elements, changing over time, technology and society. An ISMS essentially manages how to respond to threats and reduce their impact.
- Hackers: the foremost threat, growing alongside IT; today mostly profit-driven (e.g. ransomware that encrypts files).
- Internal sabotage: the strongest fortress is often breached from within — insiders can bypass safeguards.
- Third parties & supply chain: outsourcing and cloud introduce new threat models; recent semiconductor-plant incidents originated from vendors.
- Legal compliance: governments increasingly tighten security laws, adding administrative-penalty risk after breaches.
- Technology: big data and AI can be used to attack as well as defend — AI-assisted intrusion is already evident.
The ISO 27XXX family
ISO has developed a series of standards for information-security management; while locally only some are commonly referenced, these standards serve as execution references for the main clauses and each control.
ISO 27001:2022 has been published. IngSafe consultants have compiled the relevant information — please contact us for details.
Interested in adoption and consulting? Contact us and a specialist will assist you.
IngSafe