#124 Triaster's success with ISO 27001 with guest Jane Duncan
The ISO Show30 Nov 2022

#124 Triaster's success with ISO 27001 with guest Jane Duncan

Data breaches have risen by 70% globally in Q3 of 2022, reenforcing the requirement for many to seek out Information Security solutions, especially those within the tech space.

Today we speak to Triaster, who have been in operation since 1994, providing businesses with process mapping and execution software to help drive business improvement.

Triaster's Business Operations Manager, Jane Duncan, explains why they sought to implement ISO 27001, what challenges they faced and what they learned during their certification journey.

You'll learn

  • Who are Triaster?
  • Why Triaster Implemented ISO 27001
  • What did they learn from their experience?
  • What benefits have they seen as a result of Implementing ISO 27001?

Resources

In this episode, we talk about:

[00:54] Get to know Jane Duncan – Triaster's Business Operations Manager who has recently started fostering dogs for a local charity.

[01:41] Who are Triaster? In short, they build software solutions that drive business improvement. They are a thought leader in their field and strive to create new software to meet business needs.

[02:25] What was the main driver for achieving ISO 27001? In 2020, they had certified to the Quality Standard, ISO 9001, and saw the many benefits that come with ISO certification. They saw ISO 27001 as both an opportunity and a necessity due to their work within the IT industry. ISO 27001 is seen as a mark of trust and provides a central framework to improve data security.

[04:28] How long did It take to implement ISO 27001? They started looking at certification bodies and consultants to help with implementation in March 2021. The project overall lasted six months, with their assessments taking place in September and October of the same year. They also chose to recertify to ISO 9001 at the same time – this aligned both Standards under one Integrated Management System.

[06:35] If you are considering implementing multiple ISO's, it's recommended to integrate them into a single Management System. This reduces the costs of implementation and is overall easier to maintain.

[07:17] What was the biggest gap identified in Triaster's initial Gap Analysis? They had a lack of security policies in place in addition to a lack of processes that would have mitigated potential data security risks.

[08:00] What was the biggest difference ISO 27001 made? They now do regular annual SWOT and PESTLE's that are evaluated at Management Reviews. Risks identified during those reviews are added to a risk register and are used to develop the necessary objectives and controls needed to mitigate future risk.

[08:38] Other differences include the ability to track non-conformities, security risks and opportunities for improvement. They also have the confidence to prove their data security credentials to clients and have the required documentation to back it up. Tendering processes are also made easier by having ISO 27001 as it is often a requirement that can now be ticked off.

[09:25] Triaster use Infrastructure partner (who are also ISO 27001 certified) and can now hold them accountable for the services they provide.

[09:50] Jane states that they are now a much better business following the Implementation of both ISO 9001 and ISO 27001 – continually improving their processes and scrutinising working practices.

[10:54] All of the same security practices can be done by those who are homeworking at Triaster

[11:05] What has been the main lesson learned? The process if certification is a journey – it's about continually improving and truly adopting the ethos of Information Security into every aspect of the business.

[11:52] What are the main benefits? They hope their clients can see their efforts and have confidence in Triaster's ability to keep their data secure. They also now have the processes in place that drive continual Improvement.

[12:33] Jane's top tip: Document what you do as a business and look for gaps. Also, certification is a journey, and you shouldn't stop striving to improve once you achieve certification.

[13:00] What book would you recommend and why? Internal Auditing in plain English: A simple guide to super effective ISO Audits by Craig Cochran

[14:15] Jane's favorite quote: "No one is you, and that is your superpower"

We'd love to hear your views and comments about the ISO Show, here's how:

Subscribe to keep up-to-date with our latest episodes:

Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(200)

#258 What is BS 99001? Quality Management For The Built Environment

#258 What is BS 99001? Quality Management For The Built Environment

Many of you will be familiar with ISO 9001, the leading Quality Management Standard, which provides a solid foundation for managing any business. However, for certain industries, ISO 9001 alone is not...

16 Sep 44min

#257 How to meet legislative and ISO requirements in leasehold properties

#257 How to meet legislative and ISO requirements in leasehold properties

Many businesses do not own the property they operate in, this can lead to complex questions over who has ownership over certain property and facility related legal obligations. Managing areas such as...

19 Aug 33min

#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It's estimated to generate around £50 billion in economic benefit, along with the creation ...

5 Aug 45min

#255 AI Due Diligence - Information Security Checks Before You Integrate AI

#255 AI Due Diligence - Information Security Checks Before You Integrate AI

AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate...

22 Juli 19min

#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

The path towards becoming an ISO consultant is often a meandering one. It's not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We're c...

1 Juli 25min

#253 Building The Case For Health & Safety Regulations & Standards

#253 Building The Case For Health & Safety Regulations & Standards

Everyone who goes to work should have the right to go home after work. This is a sentiment that wasn't necessarily formally recognised until the 1970's here in the UK.   Health & Safety often gets mo...

24 Juni 27min

#252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

#252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certi...

17 Juni 33min

#251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification

#251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification

Watch the video interview here Carbon verification is quickly becoming a necessary step for many businesses, whether due to regulatory compliance, market demand or as part of a voluntary scheme. The...

10 Juni 34min

Populärt inom Business & ekonomi

framgangspodden
varvet
rss-jossan-nina
rss-borsens-finest
svd-tech-brief
24fragor
avanzapodden
badfluence
uppgang-och-fall
rss-inga-dumma-fragor-om-pengar
lastbilspodden
fill-or-kill
rss-dagen-med-di
rss-kort-lang-analyspodden-fran-di
rikatillsammans-om-privatekonomi-rikedom-i-livet
tabberaset
bathina-en-podcast
kapitalet-en-podd-om-ekonomi
borsmorgon
affarsvarlden