Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

101–104 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#101
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

There's a very recently announced ( https://security.googleblog.com/2021/10/launching-collaborat... ) initiative by Google, Salesforce, Okta, Slack and others to create a minimal security standard - https://mvsp.dev/ - which will hopefully reduce this overhead and encourage an improvement in security across the industry.

The 'standard' one I've been asked to complete a few times is the CAIQ:

https://cloudsecurityalliance.org/artifacts/consensus-assess...

Re: Ask HN: Is the ISO 27001 certification worth it?

#102
post #55

Earlier quoted context omitted.

We’re also certified for similar reasons. It did bring information security more in the focus of upper management, so that’s a plus. I for the time for backup encryption, getting rid of outdated servers (fuck Arch Linux, really), and everyone now has a monitored laptop, and got a info sec training.

You could have organized your processes around ArchLinux instead of battling it, really. A living, dynamically developed software will benefit a lot from ArchLinux rolling releases. Once your software becomes an ossified cash cow, moving it to RedHat makes more sense.

I'm sure that someone with enough knowledge of Arch Linux could have set it up properly, but I inherited multiple servers with three different distros (and the Ubuntu ones were on different versions). One of these was Arch Linux. It hadn't been updated in a long time, and the update simply failed. Once I got past that, it was going to break something (can't remember, but most likely the Python version). A little while later, it couldn't update anymore, because some file or package was no longer accessible. With Ubuntu (or Debian), you can at least install a new version even if some intermediate release is no longer downloadable. It's been a headache without any benefits from my point of view. By all means, run it on your personal servers, but it's an operational risk for an organization.

Re: Ask HN: Is the ISO 27001 certification worth it?

#103
post #30
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

> specific details on the physical security of an AWS datacenter So, you want to certify yourself as secure, yet you store data on other people's computers, and you don't know how they are protected?

I don't expect companies to hand out every detail about their security architecture. Security by obscurity is bad when it is the only thing you have, but it is an important part of the system as a whole.

I also wouldn't want deal with someone who tells me details that are not publicly available. If he tells me somebody else secrets, he will tell others my secrets.

There is no good answer to these questions except "this is not publicly available data".

Re: Ask HN: Is the ISO 27001 certification worth it?

#104
post #74
post #32

Earlier quoted context omitted.

> It's theatre, so it won't help actual security. I disagree with this sentiment. As a small firm who has undergone multiple security audits/certifications, I have found that the controls we added were generally practical and did improve our security.

I've seen the exact opposite thing happen: organizations that went into security engineering deficit because of stupid things they were led by an unguided audit process to believe they needed to do. Compliance is a byproduct of security, not the other way around. Never go into a compliance process without an already-clear idea of what your security practice goals are.

Looks that you don't have any idea of ISO/IEC 27001. ISO/IEC 27001 is actually a standard which forces you to think about your security practices and goals.
Post reply on HN