In a market like today’s, organizations seek to demonstrate trust to their customers and a commitment to the security of the information they handle. To this end, holding a certification in an ISO security standard or regulation represents a competitive advantage, as it is the result of properly managing security requirements in information processing.
Cybersecurity and ISO standards
Cybersecurity is something that is very popular today, but why? The increasing number of security incidents and attacks related to information and computer systems suffered by organizations today makes the need to have controls to ensure the security of devices, communication networks, and information assets indisputable. It is from this need that the concept of cybersecurity is born.
These types of attacks aim to access, modify, or destroy sensitive information of companies.
Implementing effective cybersecurity measures is not easy because, due to the large number of equipment and technologies used, cybercriminals always find new options to carry out their attacks. However, there is a way to implement data and information protection measures that makes the process of deploying those computer security measures somewhat more structured and natural.
These are the ISO standards and regulations related to cybersecurity and information security. ISO standards are standards developed and published by the International Organization for Standardization (ISO). Both ISO and IEC (the International Electrotechnical Commission) are the specialized reference for standardization worldwide. Through technical committees made up of the member bodies of both ISO and IEC, international standards are drafted with the aim of regulating specific processes in areas such as information security.
Today, these standards constitute an indispensable element in organizations’ compliance systems, granting them international prestige and recognition. The differential value that implementing ISO standards brings to organizations over their competitors is due to the fact that these certified standards are periodically reviewed and audited to ensure compliance, considerably improving how stakeholders such as customers or shareholders perceive them.
ISO standards are numbered incrementally according to their purpose and are divided into families to group those that address aspects of the same nature. The objective of these standards and regulations is to identify techniques, policies, guidelines, training, etc. in reference to their purpose (security, continuity, quality, among others).
ISO 27000 family
Among the ISO standards already mentioned, the ISO 27000 family stands out. This is a series made up of several information security standards that detail the guidelines and requirements for implementing an Information Security Management System (ISMS) with the aim of managing organizations’ information security.
Within this set of standards, the main one is ISO 27001, the certifiable reference for the entire series. This standard provides requirements for establishing, implementing, maintaining, and continuously improving an ISMS. The continuous improvement process is based on the well-known Deming Cycle or PDCA (Plan-Do-Check-Act), which consists of the four phases of Plan, Do, Check, and Act.

The other standards in the family serve as a guide and aid for implementing the ISMS. Another quite notable standard is, for example, ISO 27002. This is a best-practices guide that describes the control objectives and controls required with regard to information security.
From the same family and with a more specific purpose is ISO 27031. This is a non-certifiable standard that serves as a guide and provides a set of methods and procedures to establish aspects that lead to an improvement in the preparation of an organization’s ICT to guarantee and consolidate business continuity. In other words, the main objective of this standard is to provide continuity of services and ensure that the organization will be able to recover from a disaster situation by restoring a previously agreed operating state.
Similar to the previous case, we can mention the ISO 27701 standard, also from the ISO 27000 family. It establishes requirements for administering, managing, and protecting the privacy of the company’s personal data in accordance with regulations and laws such as the GDPR (General Data Protection Regulation). Based on the requirements, controls, and objectives of the ISO 27001 security standard, it includes guidance for protecting the privacy and confidentiality of the personal data processed in a company. It is worth noting that certification of this newer standard is only achievable jointly with ISO 27001 certification.
Other regulations and standards
In addition to the ISO standards discussed above, there are many other standards related to the world of cybersecurity.
A clear example of this is the NIST standards, the National Institute of Standards and Technology, a Technology Administration agency of the United States Department of Commerce. Among the standards it develops, SP 800-53 stands out, for example. SP 800-53 offers a list of controls that support the development of secure and resilient federal information systems. These controls are both operational and technical guidelines and standards used by information systems to maintain the security of that information.
On the other hand, there are the so-called Service and Organization Controls 2 (SOC 2). This is an international reporting standard on organizations’ cybersecurity risk management systems, produced by the American Institute of Certified Public Accountants (AICPA). These reports are developed on the controls that an organization implements in its systems and that are related to security.
Within the SOC 2 report, two types can be distinguished. SOC Type 1 consists of a point-in-time assessment. That is, an evaluation is carried out at a specific moment with the aim of determining whether the controls implemented by the organization have been properly designed and are appropriate in view of the requirements they must meet.
As for SOC 2 Type 2, it comprises a longer-lasting evaluation, generally covering around one year. In this type of report, the organization’s controls are evaluated over the agreed period of time to determine whether they have been correctly designed and function properly throughout the entire evaluation period.
On the national scene, there are security guides, standards, and instructions developed by the CCN (National Cryptologic Center) that seek to protect the security of organizations and increase their level of cybersecurity. The series developed are mainly focused on public administrations.
Of particular note in this article is the 800 series. This series is related to the National Security Framework (ENS), as it provides procedures for the correct implementation of the measures and requirements set out therein.
On the other hand, it is worth mentioning the existence of both the COSO model and the COBIT standard. COSO (Committee of Sponsoring Organizations of the Tradeway Commission) is an organization composed of private bodies, established in the USA, which is dedicated to providing a common model of guidance to entities on fundamental aspects of executive management and governance, business ethics, internal control, enterprise risk management, fraud control, and financial reporting. As for the COBIT standard (Control Objectives for Information and related Technology), it is a set of best practices for managing companies’ information systems.
At GlobalSuite Solutions we offer help and advice to all types of organizations and sectors in implementing the Management Systems required by these standards. We also have the GlobalSuite® software which, developed by our team, is a tool that enables the deployment, management, and maintenance of the requirements demanded by the different ISO standards.



