Eliminating client stress when writing security documentation

Technologists are very good at what they do, and are often pressured into explaining what they do, very simply for a project manager or a business manager.

Sometimes technologists get deflated, as they feel they have explained themselves in good detail, but a less involved person, just wants a sentence or two, that summarises what the team or person does. And that’s where well written documents can help all teams in your organisation.

We discuss several ways to make writing security documentation less stressful for organisations and easy to understand.

 

Document processes

A good documented process, or process flow map often works well, to summarise who, what, when, why and where teams need to carry out various tasks. The ISO Quality Management System ISO9001 has been very popular in the past and well utilised in the product manufacturing environment. For technology businesses, the ISO Information Security Management Standard (ISMS) ISO27001 is probably of most relevance. This will help businesses organise their own internal processes.  

Is pursuing an ISO management system likely to take stress out of an organisation?

An ISMS provides people with a framework to work under. But the ISMS means different things to different types of organisations.

 

How can an ISMS benefit a technical organisation?

Developers create data environments, and must consider the user experience (the look and feel of a data environment) balanced with access needs, and legal requirements (personal data, health data etc.)

Customer service desks are often handling problems from customers and they need to respond to customers in a timely and positive fashion, they also often face issues on handling customer data. 

Well written policy guidance can help developers create an environment in line with management and customer requirements.

 

How can an ISMS benefit a manufacturing organisation?

Manufacturers rely on data at many stages of a product development process. There may be fewer IT staff in the organisation, but the concepts of an ISMS remain the same for all manufacturing staff. 

Again, well written policies should be communicated to all staff, for their expected behaviour and can also assist in creating a positive security culture.

 

Why is a process better than a procedure?

Both have equal merit, but are aimed at different audiences. A process helps project managers and sales managers articulate themselves to clients, prospects, suppliers and even auditors.

A procedure is a document or an ‘aide memoir’, for staff carrying out a series of actions, to meet an intended outcome. A detailed task list can be referred to as a work instruction.

What is a procedure?

In an ISMS, we often have a documented security incident management procedure. This explains where a security incident should be recorded, which teams are to be involved, and when to involve other expertise (such as when to escalate to senior management, or outside assistance).

What is a work instruction?

A work instruction is a one or two-page guide of step-by-step instructions, of (using security incident management as an example) how to input relevant information into a database. If a web-portal is used to record security incidents, staff may require instructions to enable a record to be created.

Work instructions are useful for staff when doing a task for the first time. Consider a work instruction as a backup of verbal instructions.

 

So…

Well written information security documents can help all organisations manage and protect their data. Here at CSP we can help take the stress away for you, by assisting and writing information security documentation.

Leave a Reply

Your email address will not be published. Required fields are marked *