"If I was to help another company become ISO 27001 certified, I would definitely use Secure ISMS"
DigitalRoute is a Swedish company and one of the leading providers of Data Integration and Data Management solutions globally. They were in the process of implementing ISO 27001 with help from external consultants when suddenly the project seemed unmanageable; Word documents and Excel sheets accumulated, it wasn’t clear what tasks should be done and how, and the deadline began to slip.
So, Irene Lundin, who is Compliance and Special Projects Manager in DigitalRoute, decided to change course. She found Neupart and their Secure ISMS tool and met with the local consultant.
When he showed me the templates and the solution, I thought: Now I understand what the requirements for ISO 27001 are! And this tool is actually something that could help us.
DigitalRoute implemented Secure ISMS in August 2018, and by December 2018 they were ISO 27001 certified. - I can honestly say that we could never have done it this fast without Secure ISMS. And on top of that everybody in the organisation got involved in the process. Even our CEO. That was really great.
Irene Lundin, Compliance and
Special Projects Manager,
Involving the organisation
Today, DigitalRoute use Secure ISMS to handle and maintain all policies and rules related to information security. The tangible visibility of working with a tool like Secure ISMS makes it easier for Irene Lundin to receive the support she needs from everybody in the organisation. And this is also useful when she discusses risk management and other security topics with the individual system owners.
- The system owners can better understand why some systems are business critical, and why others are not. Previously they focused more on their own responsibility and their own role. Now we all see our information security in a bigger picture.
Irene Lundin also uses Secure ISMS in the onboarding process. The solution automatically sends an email to all new employees with a request to read the company’s security policies and rules. The employees must check a box and confirm that they have read the information security policy and the information security rules before they can move on in the process.
Always ready for an audit
During the ISO 27001 audit the external auditor was very pleased with what he saw in Secure ISMS. I showed him – in the solution – that all employees have read our security policy and rules. He could see how we manage our rules, and the general control points we have for com- plying with ISO 27001.
- Our next audit is in October 2019. So, until then we work continuously with making improvements, the auditor can see everything, and we can agree on where we need to improve more. Information security becomes very transparent with Secure ISMS – for both internal and external purposes, says Irene Lundin and finishes:
If I was to help another company become ISO 27001 certified, I would definitely use Secure ISMS. Otherwise I wouldn’t know how to do it. You can do a lot with Word and Excel, but I don’t think you can actually improve your information security without a system that handles the process. And I have never seen a system like Secure ISMS that was so easy to use for that purpose.
Implement Neupart Secure ISMS and use built-in templates for handling security policies.
Want to know more?
Get in contact with Esben Mogensen +45 2262 4488 or firstname.lastname@example.org