詳細検索

New Standard ISO27001 for Obtaining ISMS Certification: 2022 Migration Success Stories and Key Points (8.16 Monitoring Activities, etc.)

Avatar
by 菊池
3 min read

New Standard ISO27001 for Obtaining ISMS Certification: 2022 Migration Success Stories and Key Points (8.16 Monitoring Activities, etc.)
Translated from 日本語 • View original
菊池
菊池

Hello! This is Kikuchi, an analyst at Colorkrew Security. Up to the last blog, we have explained the new ISMS management measures, but now we are going to talk about the last three. Next, I will explain how I responded to the 11 new management measures added from this time.

"8.16 Surveillance Activities"

"In order to assess the possibility of an information security incident, networks, systems, and applications must be monitored for abnormal behavior and appropriate measures must be taken."

This management measure is an important point in ISMS, especially in which a continuous operation system is required.
As a provider of SOC (Security Operation Center) services, Colorkrew Security provides 24 hours a day, 365 days a year to monitor the security of our client companies.

In addition to our own systems, we aggregate various log information such as firewalls, endpoint logs, web servers, DB servers, and logs to cloud environments and audit logs into SIEM to detect and analyze signs of anomalies in real time.
Based on the alerts of the security products in place, the SOC team responds consistently from initial response to analysis and escalation as needed. This is one of the areas we do best.

On the other hand, there are major hurdles in building and operating such a monitoring system in-house.
・Securing dedicated security personnel
・Establishment of a 24-hour, 365-day system < selection, introduction, and operation of products such as br> and SIEM< scrutiny and tuning of br> and alerts

Many companies find it difficult in reality because many resources are required.

Therefore, it is a great advantage to outsource to an external SOC to achieve a high-quality monitoring system while reducing initial investment and operational load.
In fact, many of the companies that consult us choose to outsource SOC because of the expertise of monitoring work, speed of response, and cost balance.

In this ISMS audit, we explained how to build and operate a monitoring system within our company with evidence, and we were able to gain a full understanding from the auditors.

"8.23 Web Filtering"

"Access to external websites must be managed to reduce exposure to malicious content."

It is appropriate to set up and filter the sites that you want to block as an organization, but I think it is better to use filtering using security products first.
We had already applied it, so there was no problem in reviewing it by telling it that way.

By the way, if you're using Microsoft Defender for Endpoint, you can enable the "Network Protection" feature to block access to malicious sites.
You can enable it in Intune or Activie Directory Group Policy. It is off by default.

*Example of Intune configuration profile

Intuneの構成プロファイル例

"8.28 Security-Minded Coding"

"We must apply the principles of security-conscious coding to software development."

I think there are many cases where coding rules are created based on guidelines such as OWASP TOP10.
In addition to the review record, the review may also check the coding rules themselves (for example, when the OWASP TOP10 is updated or when a critical vulnerability is found), so it is necessary to make it a procedure.

Finally

We have explained the above 11 new management measures.
There were management measures that had already been implemented, so we were able to prepare for the examination in about half a year. I have successfully received the certification, but I must prepare for the next year's regular examination immediately.
I can't relax.

Now, as I mentioned at the beginning, support for the 2022 version of the standard will be until October 2025.
If you have any problems, please contact us.
We are particularly good at "monitoring activities", so please contact us.

Related Articles