It is well known that Security ISO/IEC 27001 is an indispensable requirement in most organizations, especially those dedicated to IT. It is not for nothing that it is one of the most implemented standards in the world having second place after the famous ISO 9001.
However, being one of the standards that require extensive knowledge of processes, policies, and technical issues of security, it has become one of the most complicated standards to implement and especially to improve. Many companies decide to hire consultants, open a quality area or even buy formats that help speed up the certification process.
No matter what mechanism you use for implementation and improvement, there are key elements to avoid the path of bitterness and reach the conclusion of many organizations “Standards are useless” “Standards are a waste of time” among many others.
What not to do in an implementation Security Management System
- Implement in record time. I know that one of the reasons why an organization decides to implement an information security management system (hereinafter ISMS) is because a customer is asking for it or because of a bidding process. However, implementing a management system in one month or even 3 months, there is a risk that the objectives of the system are weak and the real value of the management is not perceived.
- Separate the operation of the ISMS from the actual operation of the organization. There are some organizations that think that an ISMS is an obligation far from a benefit and the easiest decision is to maintain an ISMS with evidence that does not reflect the reality of the company or the business, at that moment the ISMS becomes an expense instead of an investment.
- Certify only a part of the organization. Even though this option is totally valid and is not a bad thing, since the same standard will ask you for a scope, there may also be a latent risk of falling into the previous point and having two operations (one within the ISMS and another without management). However, to avoid this mistake, you can implement the entire ISMS in the company, but for certification limit the scope, thus avoiding error number 2.
- No top management support. When a budget is allocated to the implementation of the ISMS, it is not the only action to be taken by the management. While management does not have to be involved in the operation of the system, it is of utmost importance that management always directs and assigns where it wants to go with the system, not just to obtain certification.
- Forgetting the ISMS after implementation. Or even operate it one month before the next auditor’s visit. A management system contemplates continuous improvement not intermittently but continuously. It is as if managers take action in the company when only bad things happen, when it is like that, the company will never become stable.
- Using formats without conscience. I do not see bad use of formats, even though I have been working with my own formats for years. But it is also true that by not having awareness when filling out these formats or due awareness, you can make operational errors that do not reflect the reality of the company. It is important to use the formats adapting them to the organization and not adapt the organization to the formats.
- Perform an ISMS for the audit and not for the organization. As an auditor, I can confess that sometimes it is very notorious the elaboration of documentation to facilitate the auditor’s work or even to operate the management system only for the audit. While that makes our job easier, it does not create any benefit for the business. Say no to observations that do not add value to the ISMS.
The above points are not limiting, there may be more, but in my experience, they are the most relevant. Before I finish I want to skip the ones that are illegal in certification, such as generating evidence, buying the certification, etc. A well-implemented management system can add value to your business without the need to see it as an expense and not a real investment.
Source: https://www.iso.org/popular-standards.html

“Who needs information security anyways? Let’s just leave everything vulnerable and see what happens!”
Are you serious? Information security is crucial in today’s digital world. Leaving everything vulnerable would be asking for disaster. It’s better to be safe than sorry. Ignoring it is like leaving your house unlocked and expecting no one to break in.
“OMG, who even makes these mistakes? 😱 It’s like they want hackers to win! 🙄 #seriously”
Relax, it happens. No need to overreact. Mistakes slip through, even in the best of systems. Let’s focus on finding solutions instead of playing the blame game. #positivity
“LOL, who needs security anyway? Let’s just leave our data out there for everyone to see! 😂”
Are you serious? Your lack of concern for data security is mind-boggling. It’s people like you who make hackers’ jobs easier. Wake up and start taking responsibility for your personal information before it’s too late.
“LOL, who needs security anyway? Just let all our data get hacked! 😂”
“LOL, who needs security anyways? Just let the hackers have some fun!”
“Who needs information security anyway? Let’s just leave our data vulnerable to hackers!”
Are you serious? Data breaches are a real threat that can ruin lives and businesses. We all deserve privacy and protection. Wake up and educate yourself before making such ignorant statements.
“Wow, who needs information security anyway? Let’s just leave everything wide open! 🙄”
Are you serious? Information security is crucial in today’s world. Leaving everything wide open would be a disaster waiting to happen. It’s about protecting our privacy, sensitive data, and preventing cyberattacks. Ignoring it is simply naive.
Comment:
OMG, who even makes these mistakes? 🤦♀️ It’s like common sense went on vacation! #FacePalm