Basics of ISMS Governance using ISO 27014
Dipen Das, CISM, CISSP, CRISC
CISM, CRISC & CISSP certified Cybersecurity Enthusiast | IT Risk | Cloud Security | Risk and Compliance | ISMS | ISO27001 | ISO 27005 | NIST CSF | Privacy | PCIDSS | Data Security |
“Proper governance of information security ensures alignment of information security with business strategies and objectives, value delivery and accountability. It supports the achievement of visibility, agility, efficiency, effectiveness and compliance”
What is Information Security Governance?
Information Security Governance is the process of establishing and implementing a framework that enables an organization to manage and protect its information assets. It involves the development of policies, procedures, standards, and guidelines that guide the use, protection, and management of an organization's information resources.
The goal of Information Security Governance is to ensure that an organization's information assets are protected against unauthorized access, disclosure, modification, destruction, and disruption. It provides a structured and systematic approach to managing information security risks, ensuring compliance with legal and regulatory requirements, and aligning information security with the organization's business objectives.
Information Security Governance typically includes the following elements:
What is Governing Body?
A governing body is a collective of individuals who have the authority and responsibility to formulate policies and lead an organization’s general trajectory. The collective body is responsible for decision-making and implementation on behalf of its staff, stakeholders, and the organization.
The governing body’s primary function is to safeguard the organization’s privileges and interests, as well as those of anyone who works within the organization’s framework. This body accomplishes this by ensuring that the organization operates efficiently and is capable of achieving the aims and priorities it has committed to.
What is ISO 27014?
ISO 27014 provides guidance on concepts, objectives and processes for the governance of information security, by which organizations can evaluate, direct, monitor and communicate the information security-related processes within the organization.
ISO 27014 is a standard developed by the International Organization for Standardization (ISO) that provides guidelines for information security governance. Specifically, it focuses on the role of information security governance in supporting the overall governance of an organization.
ISO 27014 is intended to be used by senior management and other decision-makers within an organization who are responsible for the governance and management of information security. The standard provides guidance on how to establish and maintain an effective information security governance framework that supports the organization's objectives and strategies.
This standard is “designed to aid organizations in effectively managing their information security strategies.” The standard offers “directions on the principles and concepts for information security governance, from which organizations can evaluate, direct, monitor, communicate and assure information security-related practices in the organization. The eleven-page standard summarizes information technology governance standards and includes a structure of six principles and five processes. The standard views IT governance as interacting with information technology governance, all of which are components of the wider framework of organizational governance.
The six principles – Objectives of Information Security Governance
“Governance of information security should ensure that information security activities are comprehensive and integrated”
The five processes
Information security governance processes have been developed to help organizations monitor and manage their information security efforts. Evaluate, direct and monitor form a cycle similar to Plan, Do, Check Act (PDCA)
The key areas addressed by ISO 27014 include:
ISO 27014 places considerable emphasis on the governance components of ISO/IEC 27001 and establishes governance objectives within this framework. It covers the incorporation of information security governance activities with other governance functions and goals
ISO 27014 is intended to be used in conjunction with other standards in the ISO/IEC 27000 series, such as ISO 27001 and ISO 27002, which provide specific guidance on the implementation of information security management systems. By providing guidance on information security governance, ISO 27014 can help organizations to ensure that their information security program is aligned with their overall business objectives and effectively managed at the highest level of the organization.
Information Security Governance is a critical component of an effective information security program. It provides a structured approach to managing information security risks and ensures that information assets are protected and managed in a consistent and systematic manner.
Building Sustainable & Resilient Cybersecurity Programs in America, Canada, EMEA, APAC, LATAM
1 年The approach described by ISO 27014 does not address all the governance requirements of ISO/IEC 27001:2022 ISMS. For registration /certification purposes, companies should always comply with ISO/IEC 27001:2022 ISMS the auditable specification. I created the ISO/IEC 27001:2022 ISMS Reference Architecture to simplify the complexity of complying with 163 control points listed in ISO/IEC 27001:2022 ISMS clauses 4 to 10. ISO 27014 only identified four procedures as part of governance, however that falls short of the ISO/IEC 27001:2022 ISMS requirements that include seven procedures. Check out my ISO/IEC 27001:2022 ISMS Reference Architecture for all the detailed requirements.