Financial Insights
No Result
View All Result
  • Home
  • Insights
    • Agriculture
      • Zambeef Products Plc
      • Zambia Sugar Plc
    • Banking
      • Cavmont
      • Investrust Bank Plc
      • Stanbic
      • Standchart
      • ZANACO plc
    • Beverage
      • National Breweries
      • Zambian Breweries
    • Energy
      • Copperbelt Energy Corporation Plc
      • Puma Energy (Z) Plc
    • Finance
      • Madison Financial Services Plc
      • ZCCM-Investment Holdings Plc
    • Insurance
      • Prima Reinsurance Plc
    • Manufacturing
      • Lafarge
      • ZAMEFA Plc
    • Mining
      • AEL Mining Services (Z) Plc
    • Real Estate
      • Real Estate investments Zambia (REIZ)
    • Retail
      • British American Tobacco
      • Shoprite Holdings Plc
      • Zambia Bata Shoe Plc
    • Telecom
      • Zamtel
      • Airtel Networks Plc
    • Tourism
      • Taj Pamodzi Hotels Plc
  • Opinion
    • Economy
    • Marketing
    • Strategy
  • Market Research
  • About
  • Home
  • Subscription
  • Try
SUBSCRIBE
  • Home
  • Insights
    • Agriculture
      • Zambeef Products Plc
      • Zambia Sugar Plc
    • Banking
      • Cavmont
      • Investrust Bank Plc
      • Stanbic
      • Standchart
      • ZANACO plc
    • Beverage
      • National Breweries
      • Zambian Breweries
    • Energy
      • Copperbelt Energy Corporation Plc
      • Puma Energy (Z) Plc
    • Finance
      • Madison Financial Services Plc
      • ZCCM-Investment Holdings Plc
    • Insurance
      • Prima Reinsurance Plc
    • Manufacturing
      • Lafarge
      • ZAMEFA Plc
    • Mining
      • AEL Mining Services (Z) Plc
    • Real Estate
      • Real Estate investments Zambia (REIZ)
    • Retail
      • British American Tobacco
      • Shoprite Holdings Plc
      • Zambia Bata Shoe Plc
    • Telecom
      • Zamtel
      • Airtel Networks Plc
    • Tourism
      • Taj Pamodzi Hotels Plc
  • Opinion
    • Economy
    • Marketing
    • Strategy
  • Market Research
  • About
  • Home
  • Subscription
  • Try
No Result
View All Result
Financial Insights
No Result
View All Result
Home Tech Cyber Security

Enhancing Information Security People Controls based on ISO 27001:2022

Andrew M Kampolo by Andrew M Kampolo
September 4, 2023
Reading Time: 4 mins read
0

Having access to reliable information is crucial for businesses and government entities. However, with the widespread use of technology in handling data, there are significant risks associated with information security that organisations must be aware of and address proactively. These risks can range from internal threats and human error to data breaches and cyber-attacks. New legislation such as the Data Protection Act of 2021 has introduced an interesting twist by mandating organizations and government bodies alike to protect personal information or any data that can identify an individual. This has accelerated the need for the implementation of stringent security measures to safeguard sensitive information owned by organisations. One way to enhance human information security within the organisation is by implementing people controls based on ISO 27001.

RELATED POSTS

FNB Zambia and Liquid Intelligent Technologies partner to offer to drive convenience through affordable data access.

Enhancing Information Security People Controls based on ISO 27001:2022

The Digital Economy: Lessons for Zambia

ISO 27001 is an internationally accepted standard for implementing a robust Information Security Management System (ISMS) that presents a comprehensive structure for efficiently managing information security. The ISO Standard acknowledges the vital role played by people in distorting or guaranteeing information security. Organisations can enhance their people security posture by adopting ISO 27001 People Controls which have full coverage of the entire lifecycle of employee security. Human Resource functions can adopt these processes and support the overall enterprise information security management systems and strategy.

Implementing a comprehensive screening process is a crucial step in mitigating potential security risks and ensuring human resource security. Organizations must be vigilant against criminal organizations seeking to infiltrate them and have insiders with access to information and systems. By conducting thorough background checks, verifying references, and implementing structured vetting processes, insider risk can be reduced, and organisations can prevent individuals with questionable intentions from accessing sensitive information. Pre-employment and ongoing screening are key controls for evaluating the trustworthiness and integrity of prospective employees.

It is crucial for businesses to have well-defined terms and conditions of employment that include information security requirements. By incorporating responsibilities for information security in employment contracts, companies can establish expectations for employee behaviour and responsibilities regarding data protection and maintaining the security of information. This helps to ensure a strong foundation for maintaining the security of information. Additionally, organisations must develop and implement access control policies to regulate the access rights of individuals within the organisation. These policies should clearly define the roles and responsibilities of employees regarding information security and establish appropriate access levels based on job functions and requirements.

 ISO 27001 places great importance on continuous education and training to empower employees with the expertise to effectively safeguard sensitive information. It is crucial to automate awareness training that educates employees about the best practices in information security. Awareness and training should be role-based to be effective and should include the key competencies required for each employee to make the right decision when faced with a challenge. Automating awareness ensures ongoing education initiatives are in place to play a vital role in fostering an environment where employees are knowledgeable about their roles and responsibilities in upholding information security standards.

An effective disciplinary process is an essential element of human security controls. ISO 27001 promotes the establishment of comprehensive guidelines for addressing security breaches and violations of information security policies. By consistently and fairly enforcing these policies, organizations can demonstrate their strong dedication to maintaining a secure environment. To further emphasize the significance of confidentiality, it is advisable for businesses to implement the practice of having employees sign confidentiality or non-disclosure agreements. These legally binding documents serve as a constant reminder to each employee about their responsibility in safeguarding sensitive information, even beyond their tenure with the organization. To ensure the proper management of access to information systems when employees leave the organization or change roles, it is important to promptly revoke their access rights and retrieve any company-owned assets they may have (such as laptops or access cards).

The increase in remote working has posed new information security challenges. ISO 27001 People Controls encourages organizations to implement secure remote working policies and equip employees with essential tools like VPNs and secure communication channels. This ensures the protection of data even outside the office environment. When incidents occur, the organisation should have a culture that encourages timely reporting of information security incidents regardless of magnitude and type of incident. Awareness training must proactively include processes and tools for employees to report any security concerns, breaches, or suspicious activities promptly. When reported incidents must be properly investigated and feedback given to key stakeholders and the person that reported the security incidents.

Buy JNews
ADVERTISEMENT

 When they start with the company, new hires should receive comprehensive welcome packets containing valuable information about the organization’s information security culture and values. The onboarding process should include guided tours of the office premises highlighting the physical security protocols, such as clear desk policy and access to the office and restricted areas. The onboarding security training should be done preferably within three working days to outline all the information security protocols of the organisations. This training is preferred to be instructor-based online or physical training. Streamlined access provisioning by ensuring that access to the system is on a need-to-know basis and done after the mandatory security training for all new hires is important to enshrine the information security culture of the organisation.

Implementing a strong information security culture within an organization requires careful attention to several key factors including management commitment, communication with employees, courses for all members, and employee commitment. When it comes to managing information security culture in an organization, there are several stages of implementation that should be considered. Schlienger and Teufel formulated a model for the management of information security culture by identifying four stages of implementation, namely, management commitment, communication with the employees, courses for all members, and employee commitment. Martins and Eloff’s study on information security culture in an organization highlights the importance of addressing nine key issues. These issues are policies and procedures, risk analysis, benchmarking, trust, management support, change management, ethical conduct, budget, and awareness.

 ISO 27001 people controls serve as a critical foundation for enhancing human security within an organization. By implementing these controls and integrating them into the onboarding process, businesses can significantly reduce the risk of data breaches and ensure a stronger defence against information security threats. ISO 27001, the international standard for information security management systems, can serve as a useful reference point when implementing and maintaining an information security culture within an organization. By adhering to the guidelines set forth in ISO 27001, organizations can establish robust processes and controls to protect their information assets.

Sharing is caring!

  • Facebook
  • Twitter
  • LinkedIn
ShareTweetPin
Andrew M Kampolo

Andrew M Kampolo

Related Posts

FNB Zambia

FNB Zambia and Liquid Intelligent Technologies partner to offer to drive convenience through affordable data access.

September 11, 2023
Cyber Security

Enhancing Information Security People Controls based on ISO 27001:2022

September 7, 2023
Cyber Security

The Digital Economy: Lessons for Zambia

September 7, 2023
Technology

inq. Digital Unveils Innovative AI Products – “The Future of Technology Is Here”

September 3, 2023
Technology

THE CONFLUENCE OF AFRICAN FINTECH

August 11, 2023
Tech

Flutterwave Rolls Out Send App, Innovative Remittances Solution in the United States and Canada

August 6, 2023
Next Post

Distribution of Loans & Advances at Half Year 2023 by Zambian Banks

The Digital Economy: Lessons for Zambia

Recent Articles

  • Lupiya raises $8.25 million in Series A round to grow its neo banking business.
  • President Hakainde Hichilema Signals Open Access to Electricity
  • African Development Bank announces investor calls for inaugural USD Global Benchmark Sustainable Hybrid Capital transaction..
  • Global Africa Business Initiative announces world-class lineup for ‘Unstoppable Africa’ 2023 event
  • FNB Zambia and Liquid Intelligent Technologies partner to offer to drive convenience through affordable data access.

Recommended Stories

ACCA Business Leaders Post Event Review

ACCA Business Leaders Post Event Review

June 21, 2023

Daily FiZ – Wednesday 04/11

November 4, 2020

Atlas Mara by the numbers – Half Year 2020 Performance

August 30, 2020

Popular Stories

    About Us

    The Financial Insights of Zambia was established in 2017 as a follow up to the success of The Financial Health of Zambia’s Premier Companies blog which was birthed as an idea that would address the challenge Zambian investors had in understanding how companies within the economy created value. Armed with the annual reports of companies listed on the Lusaka Stock Exchange, we bring business analysis and valuation of these premier companies.

    What’s New Here!

    • Lupiya raises $8.25 million in Series A round to grow its neo banking business.
    • President Hakainde Hichilema Signals Open Access to Electricity
    • African Development Bank announces investor calls for inaugural USD Global Benchmark Sustainable Hybrid Capital transaction..
    • Global Africa Business Initiative announces world-class lineup for ‘Unstoppable Africa’ 2023 event
    • FNB Zambia and Liquid Intelligent Technologies partner to offer to drive convenience through affordable data access.
    • Unifi Credit Demonstrates its Corporate Ethos and Culture at its Annual Golf Day

    © 2023 - Fizambia.com - All Rights Reserved

    No Result
    View All Result
    • Home
    • Business
    • Culture
    • Economy
    • Lifestyle
    • Health
    • Travel
    • Opinion
    • Politics
    • Tech
    • World
    • Support Forum
    • Contact Us

    © 2023 - Fizambia.com - All Rights Reserved