What is ISO 27001 BGYS (ISMS)?
ISO 27001 BGYS (Information Security Management System/ISMS) is a sensitive approach adopted to manage the organization's sensitive information. The main purpose of this system is to ensure the security of sensitive information and covers employees, information and information processing assets and business processes.
The ISO/IEC 27001 standard is a widely recognized international standard for establishing and maintaining an information security management system in an organization. It provides general principles and guidance for initiating, implementing, maintaining, and improving information security management within an organization.
ISO 27001 and its guidance standard, ISO 27002, are not technical standards, but instead provide guidelines for establishing processes and systems for information security management. To define and implement security measures specific to an organization's own sector in a harmonized manner, international industry standards such as ISO IEC TR 27019, NIST SP 800, NIST SP 800, IEC/TS 62443, and others are used.
Within the scope of the ISO 27001 Information Security Management System standard, the PDCA (Plan - Do - Check - Act) model is applied for the establishment, implementation, monitoring, review, maintenance and improvement of the ISMS.
What are the Purpose and Benefits of ISMS?
In order to ensure the effectiveness of information security, including data, information systems (hardware and software), various tools and techniques such as policies, procedures, instructions, reporting systems, and analysis systems are needed. Therefore, certain requirements stipulated by the ISO/IEC 27001 global information security standard must be fulfilled before certification can be achieved by an organization.
Based on this need, ADEO's GRC team identifies potential threats and vulnerabilities that could compromise the security of important information and information systems through tests performed by ADEO's offensive cybersecurity experts. The ADEO GRC experts then conduct studies in line with ISO/IEC 27001 standard directives, such as developing policies, procedures, documentation, asset inventory, and risk analysis. They prepare your organization for the certification audit through the PDCA cycle methodology.
Which Organizations and Companies are obliged to establish ISMS?
Legal requirements are explained in the regulations below. Accordingly, if your organization or company is within the scope of these regulations, you must establish ISMS.
- The Prime Ministry Circular (2016/28) on the inclusion of public institutions and organizations in the KamuNet network was published in the Official Gazette on December 3, 2016 and came into effect. The circular mandates that public institutions and organizations establish an Information Security Management System (ISMS) and implement cybersecurity policies and procedures for all processes, in compliance with the ISO 27001 standard. This requirement is one of the Minimum Security Requirements for Inclusion in the KamuNet Network, emphasizing the importance of ISMS implementation in public institutions and organizations.
- Capital companies/institutions providing electronic communication networks and operating the infrastructure have been required by the ICTA to obtain TS ISO/IEC 27001 Information Security Management System Certificate as of 20.07.2010.
- According to the Regulation on Facilitation of Customs Affairs, importers and exporters who apply for an Authorized Economic Operator Certificate (AEO) must obtain an ISO/IEC 27001:2013 Certificate. The General Directorate of Risk Management and Control under the Ministry of Customs and Trade has introduced the requirement to obtain an ISO/IEC 27001 Certificate as one of the necessary documents for companies applying for an Authorized Economic Operator Certificate.
- Ministry of Finance Revenue Administration Companies applying for E-invoice Special Integratorship are obliged to obtain TS ISO/IEC 27001 Certificate.
- The Electricity Market Regulatory Authority (EPDK) amended the License Regulations to make TS ISO/IEC 27001 Information Security Management System Certificate mandatory. As of March 1, 2016, companies in the electricity market sector are required to have the ISO/IEC 27001 Certificate from a certification body accredited by the Turkish Accreditation Agency (TÜRKAK). Additionally, with the amendment to the regulation published in February 2017, electricity distribution companies are required to refer to the ISO/IEC TR 27019 guidance document in addition to the TS ISO/IEC 27002 Implementation Guide in the Information Security Management System that they establish according to TS ISO/IEC 27001.
Which Steps are Followed in ISO 27001 ISMS Installation Process
The following steps are followed in the ISMS installation process to be carried out by ADEO's GRC experts:
- Preliminary preparation, field inspection, organizational structure and existing documentation structure, if any, are examined and work processes are determined.
- It is determined at which stage the organization is at for ISO 27001 ISMS installation.
- Working Team is formed, roles and responsibilities are determined.
- Necessary trainings are provided for ISO 27001 System installation and continuity (ISO 27001 Basic, Documentation, Internal Audit, Risk Analysis, Information Security Awareness Trainings).
- Working Methodologies are determined, Policy, Procedure, Instruction etc. documents are prepared.
- Asset Inventory work is carried out under the supervision of authorized personnel of the organization. These assets are: Information Assets, Physical Assets, Software Assets, Service Assets (computer and communication services, heating, lighting, power, etc.), Personnel Assets, Intangible Assets (such as reputation and image).
- Risk Analysis work is carried out with reference to the report prepared by our Security Team for the vulnerabilities and threats detected by the tests it conducts.
TS ISO/IEC 27001 Compliant Information Security Management System Consultancy
Within the scope of ADEO's TS ISO/IEC 27001 compliant Information Security Management System consultancy, we provide all the necessary support for companies and enterprises to successfully pass ISO/IEC 27001 audits. We also conduct periodic pre-audits to ensure continued compliance following the certification process.