manawize

As an ISO 27001-certified organisation – Part 3 – Transparency

As an ISO 27001-certified organisation: 3 practical changes you can implement right now

ISO 27001 really comes into its own when it’s not just about creating „rules”, but when you also have a simple, easy-to-follow plan for dealing with day-to-day situations. The following three areas typically help to quickly sort things out where the most misunderstandings, hasty decisions and damage are likely to occur.

1) Incident management: don’t wait until there’s a problem to figure it out

According to ISO 27001, it is advisable to prepare for incidents in advance (roles, tasks, reporting and response procedures), because in a real-life situation there is no time to work out who does what.

Practical tips that you can start using as early as tomorrow:

  • There should be a dedicated reporting channel (e.g. an email address linked to a ticketing system), rather than Teams, phone calls or text messages, which can easily get lost over time.
  • Please ensure that at least one designated contact person (name, contact details, when available) is specified.
  • Define three simple categories (e.g. „low / medium / critical”), and specify the key information and response times required for each one.


A real-life example:


At 16:40 on Friday, a suspicious email arrives from one of the suppliers stating that their bank account number has changed, just before a transfer is due to be made. The colleague does not forward it to others within the company, but reports it via the designated channel; the person in charge initiates the planned steps, the finance department suspends the process, and the supplier is called back via a pre-arranged, independent contact number to confirm that the email and the change are genuine.

2) Logging: when the question „What happened?” can be answered within 10 minutes

Under ISO 27001, logging is not about collecting everything, but about ensuring you have logs from which you can reconstruct events, and that you manage these in a controlled manner.

Practical tips (the bare minimum, which is already very useful):

  • Start with the items that pose the greatest risk: logins (successful/unsuccessful), administrative operations, changes to permissions, and changes to important settings.
  • Decide in advance how long you will keep it (e.g. 90 days / 12 months) and who is authorised to access it.
  • Make sure there’s a record of the checks: one brief log review per month and a ticket or note detailing when and what you checked.


A real-life example:


„A folder has gone missing” from the shared storage. Without logs, this leads to guesswork and frustration; with logs, it quickly becomes clear whether it was deleted or moved, which user made the change, and when. This allows for a targeted and swift recovery.

3) Access rights for partners and service providers

Security relating to suppliers (external IT providers, developers, cloud service providers) is a specific focus area in ISO 27001: there should be clear requirements, controlled access, and well-defined on- and off-boarding procedures.

Practical tips which, whilst expected of SMEs, nevertheless set important boundaries:

  • There should be no shared admin account: every external user should have a unique account, linked to their name, with MFA (multi-factor authentication).
  • There should be an approval process: who can authorise external authority and for how long.
  • There should be a checklist for supplier onboarding and offboarding (VPN, domain user, FTP user, passwords, documentation/handover, revocation of access rights), and there should be a record showing that the process has been completed and what has been handed over or withdrawn.


A real-life example:


You switch to a new contract management platform, and suddenly it turns out that „someone can still log in” to the old system. Without a checklist, this is a rushed process fraught with potential errors. However, if you have a process in place for this, it becomes a controlled handover: you revoke all access, and it can be verified later that this has been done.

If you’d like to set up this process with confidence, tailored to the size and operations of your company, Manawize can help with this too: ensuring that the transformation of your processes does not remain merely „on paper”, but develops into a truly functional, stable system – whilst enabling you to make the most cost-effective and optimal decisions.

If you enjoyed the article or found the information useful, follow us on our blog and social media channels so you don’t miss out on the next instalments.

Our latest blog posts:

Share it with others!

How can we help your company?

Have a question?
Would you like to give us a try?
Feel free to write to me!

Are you ready for the next step? Request a personalised quote now!
We will get back to you within 24 hours.

IT Service Request Form – New Gen
Adatvédelmi áttekintés

Ez a weboldal sütiket használ, hogy a lehető legjobb felhasználói élményt nyújthassuk. A cookie-k információit tárolja a böngészőjében, és olyan funkciókat lát el, mint a felismerés, amikor visszatér a weboldalunkra, és segítjük a csapatunkat abban, hogy megértsék, hogy a weboldal mely részei érdekesek és hasznosak.