"8.16 Surveillance Activities"
"In order to assess the possibility of an information security incident, networks, systems, and applications must be monitored for abnormal behavior and appropriate measures must be taken."
This management measure is an important point in ISMS, especially in which a continuous operation system is required.
As a provider of SOC (Security Operation Center) services, Colorkrew Security provides 24 hours a day, 365 days a year to monitor the security of our client companies.
In addition to our own systems, we aggregate various log information such as firewalls, endpoint logs, web servers, DB servers, and logs to cloud environments and audit logs into SIEM to detect and analyze signs of anomalies in real time.
Based on the alerts of the security products in place, the SOC team responds consistently from initial response to analysis and escalation as needed. This is one of the areas we do best.
On the other hand, there are major hurdles in building and operating such a monitoring system in-house.
・Securing dedicated security personnel
・Establishment of a 24-hour, 365-day system < selection, introduction, and operation of products such as br> and SIEM< scrutiny and tuning of br> and alerts
Many companies find it difficult in reality because many resources are required.
Therefore, it is a great advantage to outsource to an external SOC to achieve a high-quality monitoring system while reducing initial investment and operational load.
In fact, many of the companies that consult us choose to outsource SOC because of the expertise of monitoring work, speed of response, and cost balance.
In this ISMS audit, we explained how to build and operate a monitoring system within our company with evidence, and we were able to gain a full understanding from the auditors.
"8.23 Web Filtering"
"Access to external websites must be managed to reduce exposure to malicious content."
It is appropriate to set up and filter the sites that you want to block as an organization, but I think it is better to use filtering using security products first.
We had already applied it, so there was no problem in reviewing it by telling it that way.
By the way, if you're using Microsoft Defender for Endpoint, you can enable the "Network Protection" feature to block access to malicious sites.
You can enable it in Intune or Activie Directory Group Policy. It is off by default.
*Example of Intune configuration profile

"8.28 Security-Minded Coding"
"We must apply the principles of security-conscious coding to software development."
I think there are many cases where coding rules are created based on guidelines such as OWASP TOP10.
In addition to the review record, the review may also check the coding rules themselves (for example, when the OWASP TOP10 is updated or when a critical vulnerability is found), so it is necessary to make it a procedure.
Finally
We have explained the above 11 new management measures.
There were management measures that had already been implemented, so we were able to prepare for the examination in about half a year. I have successfully received the certification, but I must prepare for the next year's regular examination immediately.
I can't relax.
Now, as I mentioned at the beginning, support for the 2022 version of the standard will be until October 2025.
If you have any problems, please contact us.
We are particularly good at "monitoring activities", so please contact us.