ISO Standards and More 15 Dec 2023

People in the light of ISO 27001 - from weakest link to key security asset

What if we viewed people differently, not as a weakness, but as the key to effective information security?

In the world of cybersecurity, it is often repeated that people are the "weakest link." According to a study conducted by the analytics and research firm Gartner in 2022, a staggering 69%* of data security incidents were caused by employee actions. But what if we looked at people not as threats, but as the greatest asset in data protection? Increasingly, cybersecurity experts are encouraging this change in perspective.

Employees as the First Line of Defense

Fully engaged and well-trained employees can serve as the first line of defense against cyberattacks. Their ability to recognize threats, responsibly use IT systems, and report suspicious situations becomes a fundamental aspect of building a strong and effective defense system against incidents.

Therefore, it is time to see people as key participants in securing data rather than merely potential sources of threats. Investing in raising cybersecurity awareness among employees and treating them as partners in data protection can significantly enhance preventive measures and minimize the risk of cybersecurity incidents.

Effective Methods and Tools

What methods and tools can be effective in building cybersecurity awareness among employees? What steps should be taken to create a culture of security in the workplace? We encourage you to continue reading this article, where we will present specific strategies and practices that support the development of effective data protection in the era of cyber threats.

The Human Dimension of Security in ISO 27001

In the context of information security, the human dimension is an integral part of the Information Security Management System (ISMS) according to ISO 27001. Raising awareness and developing employee competencies are essential for the effective functioning of an ISMS in accordance with ISO 27001.

Turning Weakness into Strength

Security information training can transform employees from potential "weakest links" into the first line of defense. By regularly expanding knowledge and raising awareness of cyber threats, a company minimizes the risk of introducing malicious software into its internal network and, in the event of an attack, significantly speeds up detection and response times.

In addition to regular training, involving employees in the creation and improvement of information security policies and procedures can help them better understand their importance and encourage greater engagement in cybersecurity activities. By involving employees in the policy and procedure creation process, they become more inclined to follow the rules they helped establish. People are a source of innovation. Encouraging them to propose ideas for improving security and actively participate in creating security solutions can lead to more effective and sustainable security strategies.

People as Threat Detectors

Typically, employees pose the greatest threat to information security within an organization. Due to inattention or lack of appropriate knowledge, they may introduce malicious software into company systems, such as by opening an attachment or link received in a message from an unknown source or downloading programs from suspicious sites.

On the other hand, employees can also be the first to prevent dangerous software from infiltrating the company's systems because they form the first line of defense in detecting and counteracting potential information security threats. Upon receiving a suspicious message, they can report a potential threat to the security team, thus preventing its spread.

Investing in the development of employees' skills in recognizing cyber threats is not only crucial for the effective functioning of security systems but also a significant element in building a security culture within the organization.

Information Security Culture

Creating a security culture where employees feel engaged and responsible for data protection is a key element of effective information security management. ISO 27001, an international standard for information security management, promotes this approach, recognizing that effective data security is the responsibility of everyone working under the organization's supervision. Building awareness is as important as implementing technical solutions within this standard.

A security culture based on trust, education, and active engagement of every organization member allows for rapid response to potential threats and minimizes the risk of human factors in security incidents. This approach aligns with modern strategies for building robust security structures within organizations.

Active Guardians

In conclusion, labeling people as the "weakest link" in information security is not only unfair but also harmful. Labeling employees as weak points can lead to a culture of blame and fear, discouraging the reporting of security incidents and seeking help when in doubt. Instead, organizations should focus on building a strong security culture that promotes openness, collaboration, and continuous improvement. Investing in training, raising awareness of threats, and developing risk management skills are crucial in creating a system where people are seen as active guardians rather than weak links.

By shifting perspective and emphasizing the human dimension of security, organizations can significantly increase their resilience to cyber threats. To further engage in proper information security management within the organization, explore the possibilities offered by ISO 27001 implementation and certification.

*Source: https://www.gartner.com/en/newsroom/press-releases/2023-02-22-gartner-predicts-nearly-half-of-cybersecurity-leaders-will-change-jobs-by-2025

 

Article author


Lukasz Kowalski

Managing Director

Certiget.

Lukasz Kowalski is an expert in the certification body market and management system certification processes. He is the founder of Certiget – the world's first platform created to increase transparency in the certification market and help organizations make informed decisions when selecting a certification body. He gained his experience both by implementing and improving management systems within organizations and at British Standards Institution (BSI) – one of the world's most renowned certification bodies. This unique background enables him to understand the certification process from the perspective of both organizations seeking certification and certification bodies. He specializes in ISO management systems and the certification market. His articles are based on practical experience as well as the latest international standards and accreditation requirements.


Share this article