Adapting ISO 27001 to a Public Institution
Carla Carvalho, Eduardo Gomes da Silva Marques · 2019
To better face the dangers and challenges of the cyberspace, a public enterprise decided to analyse and raise the security level of its information and communication systems by following good practices in this area. The adopted methodology was based on risk management and it aimed the establishment, implementation, maintenance and continuous improvement of an information security management system in accordance with the requirements of the NP ISO/IEC 27001:2013 standard. The implementation and measurement of security controls pertaining to four sections of this standard followed the PDCA continuous cycle with one iteration. The preliminary results showed relevant advances and we were able to identify the more pressing areas and which security controls needed improvement. As an additional benefit, this methodology fostered a change in the stance of the organization, which moved from having mere perceptions on its information security levels into getting an objective knowledge of its needs.