A Brief Discussion on ISO 27001: The Dual-Track Approach of Systems and Technologies

2025-12-25

40

In today's world where information security is increasingly valued, implementing ISO 27001 has become a crucial step for enterprises to improve their cybersecurity governance. This article will briefly introduce the two main aspects of ISO 27001's advancement: the construction of systems and the updating of technologies. This two-pronged approach not only strengthens an organization's cybersecurity protection but also helps in compliance with regulations and enhances trust.

ISO 27001 is an international standard used to establish an enterprise's Information Security Management System (ISMS) to ensure the confidentiality, integrity, and availability of data.


For most traditional industries, adopting ISO 27001 is not a voluntary decision, but rather a requirement from customers, the supply chain, or the market. Especially when working with large enterprises or multinational clients, ISO 27001 is often seen as a basic threshold or a necessary condition for bidding. This has led many non-technology companies, such as manufacturers, logistics companies, and equipment suppliers, to face compliance pressures related to information security.


The core objective of ISO 27001 is to help companies establish a sustainable information security management framework. It focuses not only on technical protection but also on institutional norms and risk management. Through a series of standardized processes, companies can systematically identify cybersecurity risks, develop control measures, conduct audits, and continuously improve. This not only helps reduce the risk of data breaches and operational disruptions but also enhances external customers' trust in the company's cybersecurity capabilities.


In the next section, we can further explore how to understand the substantive meaning of ISO 27001 when companies are "required" to implement it, and how to promote it from both institutional and technical perspectives.



Dual-track advancement of systems and technologies


In implementing ISO 27001, companies need to consider both the institutional and technical aspects. Both are indispensable; the institutional aspect provides the foundation for governance and standardization, while the technical aspect ensures that protective measures are truly implemented.


- Institutional aspects (policy and governance)


The focus is on establishing an Information Security Management System (ISMS), developing policies and processes, conducting risk management and assessments, and ensuring compliance through auditing and continuous improvement. These institutional guidelines enable enterprises to manage cybersecurity systematically, rather than relying solely on temporary technical solutions.


• Establish ISMS: Establish an information security management system as the core of the overall governance architecture.

• Develop policies and processes: including institutional norms for access control, asset management, and supply chain security.

• Risk Management and Assessment: Regularly identify, analyze, and address information security risks.

• Audit and Continuous Improvement: Continuously optimize systems and control measures through internal audits and management reviews.

• Compliance with regulatory requirements: Ensure compliance with ISO27001, GDPR, local regulations, and other relevant requirements.


- Technical aspects (Technology and Controls)


This includes various cybersecurity technologies such as encryption, firewalls, system updates and maintenance, monitoring and detection, as well as disaster recovery and continuity planning. These technologies are the first line of defense for enterprises against external threats and need to be continuously updated with the emergence of new technologies (such as cloud computing, IoT, and AI).


• Technical control measures: These include technical defenses such as encryption, authentication, firewalls, and endpoint protection.

• System updates and maintenance: Regularly patch vulnerabilities, update firmware and software, and maintain system security.

• Monitoring and Detection: Import tools such as SIEM, SOC, and threat intelligence to detect abnormal behavior in real time.

• Backup and Continuity: Establish a Disaster Recovery Plan (DRP) and a Business Continuity Plan (BCP).

• New technology security: Provide additional protection and risk control for emerging technology environments such as cloud, IoT, and AI.



Institutional Aspect 1 - Establishing ISMS


ISMS (Information Security Management System) is the core of ISO 27001. It is a standardized management framework that helps enterprises systematically plan, implement, monitor, and improve information security.


Establish a cross-departmental cybersecurity team to ensure that there are responsible persons for both the institutional and technical aspects.

Review existing processes and cybersecurity measures to identify gaps.

> Develop policy documents covering access control, asset management, and supply chain security.

Seek assistance from an advisor and prepare for third-party certification.

Regular audits and continuous improvement enable ISMS to become a long-term operational system.



Institutional Aspect 2 - Policy and Process Formulation


Within the policy framework of ISO 27001, policies and processes form the foundation for an organization's information security practices. These are not merely documents, but rather guidelines for the organization's daily operations, ensuring consistent behavior across all personnel when handling information. Common policies include those related to access control, asset management, supply chain security, and incident reporting.


> Draft cybersecurity policy documents: led by management, clearly defining the goals and principles of information security.

Establish standard operating procedures (SOPs): Develop procedures for daily operations (such as account application, access control, and data backup) to avoid relying on personal experience.

> Covering supply chain security: requiring suppliers to follow the same cybersecurity standards to ensure that external partnerships do not become vulnerabilities.

Incident Notification and Response Process: Establish clear notification channels and response procedures to ensure that cybersecurity incidents can be handled quickly.

> Employee education and training: Ensure that policies are not just on paper, but integrated into daily work through training.



Institutional Aspect 3 – Risk Management and Assessment


Risk management and assessment is a core component of ISO 27001. Its purpose is to systematically identify, analyze, and address information security risks, ensuring that organizations can prioritize defense against the most critical threats with limited resources. This is not merely a technical issue, but rather a management mindset: understanding where the risks lie is essential for developing effective control measures.


Inventory of assets: First, list all of the company's information assets, including servers, databases, documents, employee accounts, etc.

Identify threats and vulnerabilities: Analyze potential threats (such as hacking attacks, data breaches, and human error) and existing vulnerabilities.

Risk assessment: Assessing the likelihood and impact of each risk, usually presented in a matrix format.

> Develop control measures: For high-risk projects, design technical or institutional protective measures, such as encryption, access control, and education and training.

Continuous monitoring and improvement: Regularly reassess as the threat environment changes over time.



System aspect 4 – Audit and continuous improvement


Auditing and continuous improvement are among the core principles of ISO 27001. It emphasizes that information security is not a one-off project, but a continuous, cyclical management activity. Through regular audits and management reviews, companies can examine the effectiveness of their systems and technical measures and make improvements based on the results. This process is typically based on the PDCA (Plan-Do-Check-Act) cycle to ensure the continuous evolution of information security management.


Internal audit: Regularly check whether policies and procedures are implemented and whether technical measures are operating normally.

Management review: Involving senior management, to confirm that cybersecurity strategy is aligned with corporate objectives.

Improvement Plan: Develop improvement measures for the gaps identified in the audit and track their implementation.

> Continuous Cycle: Through the PDCA model, cybersecurity management forms a cycle of "planning-doing-checking-improvement".

External audits: During the ISO 27001 certification process, third-party auditing bodies will periodically review a company's ISMS to ensure compliance with the standard.



Institutional aspect 5 - Compliance with regulatory requirements


ISO 27001 is not only an international standard, but it is also closely related to various local regulations and industry standards. For enterprises, complying with regulatory requirements means not only "doing a good job" in information security, but also "legally and compliantly". Common relevant regulations include the EU's GDPR, Taiwan's Personal Data Protection Act, China's Cybersecurity Law, and industry-specific compliance requirements (such as cybersecurity regulations for the financial industry).


> Review applicable laws and regulations: Based on the company's location and industry characteristics, identify the laws and regulations that need to be followed.

> Policy and Regulation Correspondence: Translate regulatory requirements into internal policies and processes, such as data protection, access permissions, and incident reporting.

Regular review and updates: Regulations are revised over time, and companies need to regularly review and update their systems.

External consultant assistance: In complex regulatory environments, seek the assistance of consultants or lawyers to ensure that the system complies with requirements.

Certification and certification: Through ISO 27001 certification, companies can demonstrate to customers and the market that they comply with regulations and have cybersecurity capabilities.



Technical Aspect 1 - Technical Control Measures


Technical controls are the most intuitive part of ISO 27001, referring to various technical defenses used to protect information assets. They range from basic access controls to advanced encryption and endpoint protection, aiming to ensure that an enterprise's systems and data have a robust defense against external threats.


Encryption technology: Encrypt sensitive information to ensure that even if the information is leaked, it cannot be used directly.

Authentication and Access Control: Implement Multi-Factor Authentication (MFA) and Role-Based Access Control (RBAC) to prevent unauthorized personnel from entering the system.

Firewalls and intrusion prevention systems: Establish network perimeter protection, block malicious traffic, and detect abnormal behavior.

Endpoint protection: Install antivirus and anti-malware tools on devices such as computers, mobile phones, and servers, and ensure they are updated regularly.

Security settings and hardening: Disable unnecessary services, restrict administrative privileges, and reduce the possibility of system attacks.



Technical Aspect 2 - System Updates and Maintenance


System updates and maintenance are an indispensable part of the ISO 27001 technical aspects. Its core is ensuring that all systems, applications, and devices are up-to-date, preventing vulnerabilities or outdated settings from becoming entry points for attackers. This is not just a routine task for the IT department, but a crucial foundation for information security governance.


Regularly patch vulnerabilities: Install official security updates and patches to prevent known vulnerabilities from being exploited.

Firmware and software updates: Not only operating systems, but also network devices, servers, and applications need to be updated regularly.

Version management: Establish update processes and records to ensure that all system versions are consistent and traceable.

Testing and Verification: Before the official update, verify the system in a test environment to avoid system interruption caused by the update.

Asset inventory and maintenance: Regularly review all equipment and systems, and retire outdated versions that are no longer supported.



Technical Aspect 3 - Surveillance and Detection


Monitoring and detection are crucial defenses within the ISO 27001 technical framework. Their purpose is to provide real-time insights into the status of systems and networks and to respond quickly to anomalies or attacks. It's not merely about deploying technical tools, but rather a continuously operating monitoring mechanism that ensures businesses can detect problems immediately.


Import SIEM (Security Information and Event Management): Centrally collect and analyze logs from various systems to quickly identify abnormal behavior.

Establish a SOC (Security Monitoring Center): The system is monitored 24/7 by professionals to ensure that threats can be dealt with in a timely manner.

Threat intelligence integration: Utilize external threat intelligence platforms to gain early access to the latest attack methods and vulnerability information.

> Abnormal behavior detection: Import AI or behavior analysis tools to identify atypical user or system operations.

Incident reporting process: Establish a clear reporting and response mechanism to ensure that detected incidents are handled quickly.



Technical Aspect 4 - Backup and Sustainability


Backup and continuity are key elements in the technical aspects of ISO 27001, aiming to ensure that businesses can quickly recover and maintain core business operations in the face of unforeseen events such as system failures, natural disasters, and cyberattacks. This section typically covers Disaster Recovery Planning (DRP) and Business Continuity Planning (BCP), emphasizing that "even in the event of an accident, the business must not be shut down."


Disaster Recovery Plan (DRP): Plans how to quickly switch to a backup system or off-site backup in the event of a system or data center failure.

Business Continuity Plan (BCP): Ensures that critical business processes continue to operate during a disaster, for example, through alternative processes or temporary resources.

Data backup strategy: Establish a regular backup mechanism and ensure that backup data is stored in a secure off-site environment.

> Drills and tests: Conduct disaster drills regularly to verify the feasibility of the plan and familiarize employees with the response procedures.

Multi-layered redundancy: This includes not only IT systems, but also the redundancy design for personnel, supply chains, and communication channels.




Technical Aspect 5 - New Technology Security


With the widespread adoption of emerging technologies such as cloud computing, the Internet of Things (IoT), and artificial intelligence (AI), enterprises must pay special attention to the cybersecurity challenges in these environments when implementing ISO 27001. While new technologies bring efficiency and innovation, they also introduce new risks, such as cloud data breaches, IoT devices becoming attack entry points, and the misuse of AI models. ISO 27001 emphasizes that enterprises need to implement additional protection and risk management for new technologies.


> Cloud security: Ensure cloud service providers meet cybersecurity standards and implement encryption, access control, and multi-layered protection.

IoT Protection: Configure security settings for connected devices to prevent vulnerabilities caused by default passwords and outdated firmware.

AI and Data Security: Establish access standards for AI models and datasets to prevent the misuse of sensitive data.

Third-party vendor management: For vendors of new technologies used, they are required to comply with ISO27001 or other cybersecurity standards.

Continuous monitoring and updates: The new technology environment changes rapidly, and enterprises need to regularly review and update their protective measures.



Dual-track integration and implementation challenges


Institutional and technological aspects must work together; otherwise, problems such as "having systems but not implementing them" or "having technology but not governing it" are likely to occur.


Common challenges

- Staff resistance: Habits are hard to change, and procedures are difficult to implement.

- Insufficient resources: Small and medium-sized enterprises often lack budgets.

- Cross-departmental coordination: Management and IT departments are prone to working independently.

- Short-term compliance vs. long-term improvement: Focusing solely on certification while ignoring sustainability.


Breakthrough Method

- Seek support from senior management.

- Implement it gradually, starting with high-risk areas.

- Establish a cross-departmental cooperation mechanism.

- Continuous education and training to reduce resistance.



Import process and practical steps


Implementing ISO 27001 is not a single action, but a gradual process. Companies need to advance it on both the institutional and technical levels to ensure its successful implementation.


Typical process

1. Take stock of the current situation: Understand the existing cybersecurity measures and gaps.

2. Establish ISMS: Establish a governance structure and define the division of responsibilities.

3. Develop policies and procedures: Draft and implement cybersecurity standards.

4. Implement technical measures: Encryption, firewalls, monitoring and other protective measures.

5. Risk Management and Audit: Continuously review and improve systems and technologies.

6. Certification audit: An audit will be conducted by a third-party organization to obtain ISO27001 certification.



Benefits of enterprise implementation


ISO 27001 is more than just a compliance tool; it delivers long-term corporate value.


Main benefits

- Reduce risks: Reduce incidents such as data leaks and system outages through a dual approach of systems and technology.

- Enhance trust: Customers and partners are more willing to work with certified companies.

- Market competitiveness: ISO27001 certification is often a threshold for entering large supply chains or international markets.

- Internal efficiency: Institutionalized processes make cybersecurity management more orderly and reduce the chaos of impromptu responses.

- Sustainable operation: Continuous improvement mechanisms ensure that cybersecurity capabilities are updated as the environment evolves.



Conclusion – From Compliance to Value


The implementation of ISO 27001 is not just about "getting a certificate" or "meeting customer requirements," but also a long-term cybersecurity governance strategy.


Key points

- Compliance is just the beginning: We will promote compliance on both the institutional and technical levels to ensure that companies can meet international standards and regulations.

- Value is the goal: Through continuous improvement, companies can reduce risk, increase trust, and demonstrate competitiveness in the market.

- Sustainable operation: Cybersecurity management is constantly evolving and has become part of the corporate culture, supporting long-term development.


ISO 27001 is a significant milestone for enterprises in moving from "passive compliance" to "proactive governance." When systems and technologies are truly integrated, cybersecurity is no longer just a cost, but an asset that can create trust and value.

知識主題
永續期講座

We use our own and third-party cookies for analytics and to show you ads based on your browsing habits and profile. For more information, see our Privacy PolicyPrivacy Policy.