Secure with a System: Do I Need an Information Security Management System?
Many companies, especially small and medium-sized enterprises (SMEs), are increasingly asking themselves in times of growing IT attacks to what extent they can effectively and economically protect themselves against risks.
They usually ask questions such as:
- How can my company set itself up securely?
- Do I need an Information Security Management System (ISMS)?
- What level of security should I aim for?
- How can I start?
However, practice repeatedly shows that companies act too late - as the following case study illustrates:
The medium-sized company Trade Universe, operator of an e-commerce trading platform for corporate customers, falls victim to a ransomware attack shortly before the end of the financial year, in which important customer data is stolen and encrypted. When the security incident is reported to the customer, the Information Security Officer (ISO) employed at Trade Universe is requested by his customer from the automotive industry to analyze the incident precisely, determine the actual damage, and immediately initiate the already requested certification according to Trusted Information Security Assessment Exchange (TISAX). Since a data leak could not be ruled out, a report is also made to the competent state data protection officer in accordance with the General Data Protection Regulation (GDPR). The latter requests Trade Universe to present its documented technical and organizational measures (TOMs). To better protect itself against such risks in the future, the management of Trade Universe now decides to take out cyber insurance. In discussions with the insurance representatives, it turns out that the company must introduce an Information Security Management System (ISMS) according to VdS 10000 to conclude such a policy. The management of Trade Universe is now asking how they can meet all these requirements and avoid a similar incident in the future.

How does a company set itself up securely?
In principle, the initial goal is to capture the following points using threat analysis/threat modeling:
- What assets/protection objects are there?
- Against what should these assets be protected – what level of protection is required?
- What security measures result from the determined protection requirement for the captured assets?
Identification of Assets
The goal in the first step is to capture all information requiring protection that is processed within the business processes and to determine its protection requirement via protection goals (confidentiality, integrity, and availability).
In addition, corresponding IT applications, the IT systems on which they are operated, their locations, and the networks over which the information is transmitted should be captured centrally. In this way, a comprehensive overview of the information network to be protected should be created.
Identification of Threats and Risks
After identifying all assets, the next step is to identify specifically existing threats for each of these objects, capture the resulting risks, and finally evaluate them. The basis for this risk assessment is the classification of each risk according to potentially resulting damage linked with a probability of occurrence. This results in a risk classification that ultimately makes it possible to define the respective risk strategy – mitigation, acceptance, transfer, or avoidance – for each individual risk.
Definition of Security Measures Using an Action Plan
If there is a comprehensive overview of the identified risks and a decision from management on how to handle individual risks based on a risk strategy, an action plan can then be drawn up, approved, and successively implemented. This action plan includes all technical and organizational measures to minimize the identified overall risk in a risk- and resource-oriented manner.
For Trade Universe, this means that the ISO, following the security incident, checks all assets again as part of a threat analysis to make adjustments if necessary. In this analysis, the ISO can be supported by an external security service provider to additionally obtain an independent and neutral assessment of the threats and risks.
Who needs a management system?
If you want to permanently avoid security incidents like the one exemplified in the case study, the presented risk analysis and action planning must be carried out not only once but repeatedly. This is ideally embedded in a targeted company-wide strategy. Starting from the management, through middle management to the employees processing information, information security must be established throughout the organization.
The instrument for the efficient, long-term establishment of such a security culture is the introduction of an ISMS. The overarching character provided by a management system makes it possible to clearly define the responsibility of each individual in a bundled security process and to make every person aware of their responsibility in order to achieve the desired security goals.
The decision for or against an ISMS is based on four subject areas:
- Which regulations must be complied with?
- What goals does the company pursue?
- What is the threat situation?
- What requirements and specifications do customers and partners set?
Applicable Laws and Regulations
Among the regulations and laws to be complied with that have an impact on information security, for almost all German companies, compliance with the General Data Protection Regulation (GDPR), the Works Constitution Act (BVerG), the Trade Secrets Protection Act (GeschGehG), as well as Articles 2 and 10 of the Basic Law, the "Principles of Proper Accounting" with GoBD and GDPdU, the Commercial Code with § 37a in connection with § 257 HGB or §§ 145-147 AO, §§ 238-239, 257-261 and the Social Code I § 35, X §§ 67-78 are to be mentioned. However, this list is only an excerpt of the most important legal requirements and is by no means complete. A listing of the binding legal requirements for a company shows, depending on the business environment, whether specific regulatory requirements regarding information security exist. An example of this is the additional compliance with the BSI Act according to the BSI-Kritis Ordinance for certain industries and companies.
Company Goals
Company goals that can have a medium- or long-term impact on information security are, for example, a planned relocation of business processes to the cloud, planned inorganic growth, or the relocation of business units abroad.
Specific Threat Situation
Special threat situations for a company result in particular from the business model, such as strong networking, activities in e-commerce, or dependencies on one or more dedicated suppliers.
Requirements from Customers and Business Partners
Additional requirements and specifications that have an impact on information security usually arise from the customer side as well as in relationships with business partners. These could, for example, be industry-specific specifications, such as a requested TISAX certification or compliance with additional requirements from the BaFin issued BAIT and VAIT or the PCI-DSS specifications when dealing with credit cards.
In summary, the following conclusions can be drawn from these subject areas: The more extensive the requirements and company goals are, and the greater the threat situation and dependencies on a supplier or customer, the simpler and clearer the management decision to establish an ISMS should be.
Regardless of how high the current or aimed-for security level of a company is, it should be the goal for every medium-sized company with approximately 50 employees or more to introduce a simple ISMS early and in small steps, at least in the medium term. From a technical point of view, a formal certification by an independent certification body is not always necessary. Rather, the goal is to integrate information security early, structured and systematically within a company. In this way, damage caused by security incidents and larger, later efforts such as rushed, expensive certification projects can be avoided.
With reference to the Trade Universe case study, these considerations mean that after the described critical security incident with the disclosure of sensitive customer data, the introduction of a certified ISMS is urgently required. Only with continuous, regular control and management of security goals at the management level can the causes for such security incidents be meaningfully identified and eliminated in the long term through suitable and well-thought-out security measures. Furthermore, a cyber insurance policy can be concluded more easily by introducing a certified ISMS. In addition, the currently existing strong customer dependency and binding to the automotive industry are taken into account. Furthermore, this decision potentially even offers the possibility to perceive new customers and business opportunities from this environment.
What level of security should be aimed for?
Once the decision to introduce an ISMS has been made, the first question is which framework to use. Fundamentally, there are various frameworks and approaches for a company to establish information security. A closer examination of the core business of each company as well as the four subject areas mentioned above – laws and regulations, company goals, specific threat situation, and requirements from the customer and partner environment – quickly shows how high the requirements for information security are.
If a company, for example, serves customers from the automotive industry, either a certification according to ISO 27001 or, increasingly often, the industry-specific TISAX certification is requested in the concluded contracts.
If a company is active in the financial sector, it is usually subject within Germany, among other things, to the rules of the Payment Card Industry Data Security Standard (PCI DSS), or the banking supervisory requirements for IT (BAIT) or the insurance supervisory requirements for IT (VAIT) of the Federal Financial Supervisory Authority (BaFin). These requirements are based on national or international standards, such as the IT-Grundschutz of the Federal Office for Information Security (BSI), as well as the ISO/IEC 270XX standard family.

If there are no binding requirements for information security from the core business so far, the VdS 10000 framework offers a technically sound entry into information security. These guidelines, issued by the VdS Schadenverhütung GmbH for SMEs, are a solid framework of measures that help to view the interaction of people, IT devices, and communication media over nearly the entire cycle of all activities in a company organizationally, procedurally, physically, and technically. In this context, it is important to carry out the organizational planning before the often rather uncoordinated technical implementation. On the basis of these security measures, a certification according to ISO/IEC 27001 or industry standards such as TISAX can later be initiated with less additional effort in the event of changing market conditions and the definition of new business goals.
The following figure shows an overview of the sketched, different approaches:

For the company Trade Universe from the case study, an ISO/IEC 27001 certification is recommended for the reasons listed. The effort involved in certifying according to ISO/IEC 27001 justifies orienting oneself towards the requirements of TISAX already. Thus, the management still has the option to certify additionally according to the industry standard later and can further use resources more efficiently and preserve future opportunities for other markets and industries.
How can one start?
In cases where there is no specific budget for information security in the company at the beginning, it is recommended to approach the topic gradually. Ideally, as a first step – if not already present – a person with a technical background and leadership experience is appointed as ISO by the management. This person is tasked by the management to analyze the goals and need for information security for the company and its business units, in order to derive strategic goals as well as concrete measures and budget them.
If there is no suitable employee in the company for such a task, an external consultant can be brought in as an external ISO. The goal is initially to clarify the following open questions in a risk-based manner, focusing on critical assets, as explained previously:
- Which legal requirements and business goals are binding?
- What contractual requirements for information security do customers, suppliers, and business partners set for the respective company?
- Which critical IT resources exist in the company?
- Is there already a company-wide risk management that addresses information security?
- Which guidelines and usage regulations already exist?
- How high is the awareness, particularly within the business units decisive for competition?

Once these and other questions have been carefully answered, the next step in the initiated security process should be to define, at the management level, which business goals for the protection of information and know-how are to be pursued by the company in the future. If project undertakings such as the digitalization of business processes or efficiency increases in IT are already being discussed, these offer good entry points for the discussion of an IT strategy that takes information security into account.
If clear security goals have been defined by management in the further course, a sensible security strategy for the organization can be developed by the ISO, as described at the beginning of this article. Internal measures and concrete requirements can be derived and a lean set of rules can be set up. At this level, adequate and efficient processes can be defined and described, and responsibilities can be determined. This also includes topics such as the Business Impact Analysis (BIA) or, linked to this, Business Continuity Management (BCM).
Once these organizational tasks have all been completed or are far advanced, it is useful at this point to focus on IT security and technical topics. Here, the IT infrastructure should first be analyzed with regard to protection requirements and adjusted if necessary. In the planning of new IT landscapes or expansions, especially through the use of cloud solutions, the ISO or experts employed by them, such as an IT security architect, should be involved early on. Also the initiation and planning of physical protection measures such as access control systems, video surveillance, or intrusion and sabotage protection are to be addressed now, depending on the protection requirement determination. Not least, the sensitization of employees should be addressed and improved through an awareness campaign.
With reference to the Trade Universe case study, these considerations mean that after the described critical security incident with the disclosure of sensitive customer data, the introduction of a certified ISMS is urgently required. Only with continuous, regular control and management of security goals at the management level can the causes for such security incidents be meaningfully identified and eliminated in the long term through suitable and well-thought-out security measures. Furthermore, a cyber insurance policy can be concluded more easily by introducing a certified ISMS. In addition, the currently existing strong customer dependency and binding to the automotive industry are taken into account. Furthermore, this decision potentially even offers the possibility to perceive new customers and business opportunities from this environment.
On 12.08.2021 in the category Data Security published.
