Security-training is cathartic - Weagree

Security-training is cathartic

You’re lucky if your organisation has a strong orientation on IT security. Needless to say, strict compliance with policies and procedures mitigating IT security risk becomes increasingly important. And some discipline and structure are helpful.

Surprise

We see that in many organisations, a well-structured, systematic approach to risk management is often absent. Often to our surprise, also. And this is what makes ISO 27001-certified organisations stand out. Certified organisations follow meticulously structured procedures and document compliance with their policies:

  • Onboarding team members (detailed IT-security awareness training)
  • Software development, testing and releasing, encryption
  • Hosting (ISAE 3402 Type II SOC2) according to the highest standards in Europe
  • Handling of incidents (e.g. bugs, irregularities) and root cause analysis
  • Introducing changes in ways of working
  • Periodic al risk assessments and ongoing monitoring

Cathartic

Especially the risk assessment is cathartic (louterend) for lawyers to follow. There are several methods, and unconsciously, every lawyer will probably follow them. But it is sharpening the mind if you conduct a systematic, structured risk assessment regularly.

This update is not to tell you that our eyes opened in the past weeks, but rather to encourage you to do what we did three years ago. Going through the process of ISO certification, including the extensive risk assessments, is cathartic for any legal professional.

Ready for recertification

Weagree is entering the third year of our ISO certifications. So we are already well aware, and properly on track (in two years’ time, we encountered only one ‘minor non-conformity’) and every year, we receive compliments from our internal and external for how mature we had set up our ISMS (information security management system).

ISO 27017 and 27018

On top of ISO 27001, Weagree also has certifications for ISO 27017 and ISO 27018, which means, simply put, that Weagree enables its customers, through the Weagree Wizard, to comply with their IT security standards and GDPR. All that is needed to bridge the gap of we-cannot-know-what-our-customers-want, is an SLA in which the configuration of settings and features is written down. Yep, an SLA is not only about response times for reported irregularities.

Security Scorecard: A

Since 2017, Weagree is also scrutinised for its online presence. The leading monitoring solution, SecurityScorecard, gives us a solid “A” ranking (highest possible). Today, there is a finding regarding our weagree.de domain that notches us down to 95%, but once reviewed and approved, we should score 98.8% again. Did you check your organisation on SecurityScorecard?

As Weagree has such a strong emphasis on IT security, you will not be surprised that our auditors hardly find any non-conformities. Very comfortable for you.

Terms of Use

I hereby accept (or reconfirm my acceptance of) Weagree’ Terms of use, in which:

Terms of Use

I hereby accept (or reconfirm my acceptance of) Weagree’ Terms of use, in which: