The foundation of a safe technology environment is running a quality operation, as described above. We got there somewhat backwards, though.
We started with implementing an ISO 27001:2022 information security policy and associated standard operating procedures. Once we did some assessments regarding our performance and our ISO 27001:2022 information security policy, we realized we had to go back and implement the ISO 9001 quality management system.
The next step in our evolution was to address issues from highest to lowest risk. We use the CIS Controls roadmap provided by the Center for Internet Security:
The System Analysts, along with Central Services, maintain controls 1, 2, 4, 7, 8, 10, 16, 17. Additional controls require implementation by the Project Department as decided with your Technology Officer.
With these kinds of tools, we can effectively monitor your system and look for weak points that could open up the potential for security breaches. With the help of the XL.net team, we can address and fix issues as they appear.