Welcome to Protify.

In accordance with cookie legislation and our privacy policy, we only place strictly necessary functional cookies. 😊

For visitor analysis, we use Google Analytics (also cookieless). May we also place some Google Analytics analytical cookies to gain a better understanding?

Aragorn: practical case ISO 27001 in SMEs

Written by Protify

Are you an SME owner? Do what fits your organization.
The practical case of Aragorn

An ICT specialist, itself a medium sized organization, with many customers in the SME sector, is well familiar with the challenges of information security. What are common issues in information security and specifically in the implementation of ISO 27001? In this practical case, Aragorn shares its experiences.

About Aragorn

Aragorn has specialized in high quality services in the field of ICT infrastructure for more than 35 years, with a specialization in cybersecurity solutions. In a time in which technology is the beating heart of many organizations, they provide customized ICT solutions for SMEs with 38 technically highly skilled employees.

The reason

Quite some time ago, a potential customer in the healthcare sector was the reason for Aragorn to start with ISO 27001 certification. This customer of Aragorn, who has now been a customer for years, indicated at the time that ISO 27001 certification was a condition for entering into a collaboration.

The approach

“Because of our field of work, we were already well organized in terms of the technical measures around information security. With that as a starting point, we started looking at the existing way of working and possible improvements. For example, we added a specific ISO 27001 theme, such as management review. For us, it was very clear from the start that we did not want a paper tiger.”
Martijn Lafeber, director of Aragorn.

Aragorn was consciously looking for a solution that would allow ISO 27001 to align with the existing way of working. ISO 27001 had to become a natural part of daily activities.

Resistance

“People stay at Aragorn for a long time. As a result, part of our employees had already experienced ISO 9001 certification in the distant past. The memories that remained were mainly about many additional and unnecessary records. This meant that part of the organization was skeptical at the start of the ISO 27001 project.

A practical and pragmatic approach with the implementation of the ProActive Compliance Tool (PCT) made the difference. People had to become convinced that this project would not be a repetition of the old experience.

Internal communication was also used very consciously in this. For example, by continuously giving presentations with updates.

At those moments, we showed employees that we were not planning to change an extreme amount. Even more importantly, we always reasoned whether and why a change was necessary,” says Martijn.

Security Officer tailored to fit

An important role in the implementation of ISO 27001 is that of the Security Officer. At Aragorn, they chose to split that role. “Technically strong people are often somewhat reluctant when it comes to administrative recording. We chose to really deploy people according to their strengths. That is why we have an Operational Security Officer who takes care of the administrative part. The Technical Security Officer adds value through his technical knowledge. Together, they promote developments in the field of information security within the organization and ensure embedding. That works well for us.”

From his role as director, Martijn sets the right example himself. He visibly complies with all agreements made around information security. That is important for support.

Results

Aragorn has been able to welcome several new customers because ISO 27001 certification was one of the selection requirements. The growth of organizations that have to deal with NIS2 also means that more and more attention is being paid to assessing chain responsibility.

The ISO 27001 implementation with the use of the PCT ensures that Aragorn continues to improve continuously. “It helps us keep focus on innovation and proactive support for our customers.”

The most common improvement point

“What we really encounter very often at organizations is that an authorization matrix is missing or incomplete.” Aragorn is asked to technically create user accounts. It quickly becomes clear that there has actually never been proper consideration of who should be assigned authorizations and, above all, from which roles those authorizations should be granted. “Especially in SMEs, where various roles are often held by one person, we regularly run into this.” It is actually an HR issue and not an ICT issue. Customers who have this properly organized, for example, work with an automatic connection from AFAS software. As soon as a new employee is added in AFAS, the account is created with the correct authorizations. Technically, all of that is easy. It saves a great deal of work. The condition is that proper thought is given in advance to a complete authorization matrix. Think about rights based on specific job profiles instead of based on the individual.”

Why Protify

“Protify & Aragorn have known each other for a long time. Because we partly serve the same customer group, we understand SMEs well. The collaboration always runs very smoothly. So when we wanted to certify ourselves, choosing Protify was the obvious choice.”

Aragorn and Protify now actively seek collaboration with customers.

The employees of Aragorn are technically strong. Protify provides substance to policy related issues. “That is where we complement each other. In this way, we jointly offer the Security Quickscan.”

This Security Assessment is customized and fully tailored to the specific organization. Together with Protify, we pay attention to the complete ICT security landscape. Both policy based and technical.

Do you also want to achieve ISO 27001?

Are you considering taking the step towards ISO 27001 and do you want both the technical and policy based perspective to receive attention?

Feel free to contact us for a non binding introductory meeting. Together, we ensure that your organization works on information security in a way that fits you.

Avatar photo

Protify

For more information, please follow us on LinkedIn

DialogueTrainer: An ISO 27001 Implementation