Skip to content

Quick question

What is DIN ISO/IEC 27001:2015?

Ensuring security: Uwe Spindler explains in a short interview why the ISO 27001:2015 standard is so important for organisations.

Doppelbelichtung einer Industrieanlage mit Schornsteinen und ausgestreckten Händen, die Umweltschutz oder Verantwortung symbolisieren.

20th July 2017

Ensuring security: DIN ISO/IEC 27001:2015 is the leading international standard for information security management systems. It applies for companies and other organisations and defines the most important rules that ensure that data and IT processes are protected as well as possible. In a short interview, Uwe Spindler from TÜV NORD explains the sectors where the standard is particularly important and why the standard is absolutely essential nowadays.

#explore: What is DIN ISO/IEC 27001:2015?

Uwe Spindler: DIN standard ISO/IEC 27001 concerns standardisation of information management systems. The aim of the standard is to ensure and safeguard the confidentiality, integrity and availability of information. In principle the standard can be used for all types of organisations in all sectors, but of course there are areas of particular relevance such as banking, telecommunications and IT, where information security – which does not only mean IT security, but refers to all information needing protection – plays a major role.

And, alongside the ‘basic standard’, 27001, there is an entire 27000 family, containing further supporting and sector-specific standards and also technical reports which deal with additional requirements and recommendations. This area of standardisation is developing all the time – current themes include the Cloud, network security, telecommunications and many more.

About Uwe Spindler

Uwe Spindler performs audits and certifications at TÜV NORD companies, among others to ISO 27001, and therefore helps them to demonstrate the effectiveness of their information security management systems. He is also responsible within the Business Development area for support of the international TÜV NORD companies in the introduction of IT-related certifications.

This area of standardisation is developing all the time – current themes include the Cloud, network security, telecommunications and many more.

Uwe Spindler

TÜV NORD

Why is this standard so relevant at the present time?

Uwe Spindler: Information technology is becoming ever more important for all organisations, and the themes of digitisation, networking and globalisation are central. Against this backdrop, at the same time cybercrime is growing, which can put entire organisations out of action with targeted attacks – such as happened recently, for example, with the worldwide WannaCry attack. Preventive introduction of an information management system is an important protective measure in order to overcome potential security weak points within an organisation. In particular networked enterprises which have branches all over the world, for example, and which make use of very extensive data networks, are very open to attacks from the outside.

Certification according to ISO 27001 provides a competitive advantage for these organisations: it means that they can provide convincing evidence to customers and partners that they handle sensitive information in a way that is both committed and trustworthy.

#explore: What do you look for during certification?

Uwe Spindler: We assess if the companies have effectively implemented the comprehensive requirements as regards information security management systems. For in order to achieve certification, on the one hand they have to operate a management system on the basis of the so-called High Level Structure – comparable, for example, with ISO 9001 – and on the other hand they must implement all the relevant measures for protection of information. Annex A of ISO 27001 contains 114 such measures. Through introduction of a unified framework – the High Level Structure – various different management systems can be combined and operate together as an integrated management system.

#explore - The Online Magazine by TÜV NORD

This is an article from #explore. #explore is a digital journey of discovery into a world that is rapidly changing. Increasing connectivity, innovative technologies, and all-encompassing digitalization are creating new things and turning the familiar upside down. However, this also brings dangers and risks: #explore shows a safe path through the connected world.