Good security is not a Tick Box exercise
Many companies quite rightly use national and international security certificates and accreditation, to show how seriously they take Cyber Security to protect internal and customer data. However, this is not the full story and organisations are still subject to attack. So, are they worth the effort?
You may be mandated to gain certification in order to work with specific customers and suppliers, particularly with the UK public sector. Or you may even self-select certification to get an additional string to their bow regarding marketing a differentiator? Either way it seems to be the way organisations are moving… so what should you focus on?
Which Certification?
There are many security standards that organisations can select to prove their status as good, secure data processors/controllers. The available certifications to enhance their reputations range from:
- Cyber Essentials (Plus) – the relatively new government backed scheme developed to fit for all companies and organisations,
- International security standards such as ISO27001,
- More stringent industry standards, such as Payment Card Industry Data Security Standard (PCI-DSS) and Health Insurance Portability and Accountability Act (HIPAA).
Whichever standard is selected, there will be forms to fill, probably remediation activities and possibly external attestation to organise. The associated projects to complete these activities will be directly proportionate to the amount of evidence needed to gain this certification.
Great – we did it. So what now?
Once achieved, this is a great chance to celebrate and start your marketing promotions, but there are some areas to be aware of when considering certification.
However, any internally or externally attested certification is performed at a specific point in time. This does not mean that 6 months later, or even 1 day, that the assessed security controls are effective and active. So how can you make the most of the new certification if it was only valid for a day?
Obviously, you can perform regular audits on the controls to ensure that they are still implemented and not forgotten. But who likes an audit? And do regular audits really add value when you can spend time on your daily business-improving tasks?
The most efficient way is to embed security into the decision process. During meetings or whilst implementing changes just by asking ‘Will this break our certification status’ gives the opportunity to double check. This ongoing compliance exercise takes us less time, will result in less re-work (if asked early enough), and will make the recertification process a lot simpler. Wins all round.
Summary
So, certifications do allow you to showcase the importance organisations place on securing their data, but this should be a starting point for ongoing protection. Good security is not a tick box exercise, its continuous.
