An independent ISO 27001 internal audit of a data centre operator’s information security management system confirmed that newly integrated facilities met its standards and gave management the assurance to proceed to external recertification.

THE CHALLENGE

A global data centre operator maintains an information security management system (ISMS) certified to ISO/IEC 27001 across its Australian portfolio. After acquiring a group of additional data centres, it had to bring those facilities into its existing, mature ISMS. This meant migrating legacy systems, standardising security procedures and aligning security culture across old and new sites. An independent internal audit of the expanded ISMS was a core governance requirement and a prerequisite for external certification. The work was time-critical, because the external recertification audit had been brought forward to an earlier schedule. The operator needed an efficient assessment of a large and varied portfolio that would confirm the integration had worked and give management the confidence to proceed with external certification.

OUR APPROACH

Agilient carried out an independent internal audit of the ISMS across the Australian portfolio, using a method designed for efficiency and minimal disruption. The audit began with a detailed desktop review of security documentation, including policies, procedures, risk registers, training records and the findings of earlier external audits. This allowed Agilient’s auditors to assess the design of the ISMS and its conformity with ISO/IEC 27001 before going on site. A focused on-site assessment followed at the operator’s head office and key data centre facilities. The team carried out physical inspections, interviewed personnel from the security and compliance function and spot-checked critical controls to confirm they were operating effectively. A particular focus was confirming that non-conformances raised in earlier audits of the acquired facilities had been remediated through their integration into the operator’s more mature control environment. The findings were then documented in a formal internal audit report for management.

THE OUTCOME

The operator received a formal internal audit report giving leadership a clear, independent view of its ISMS across the unified portfolio.

Related services: security audit services. Sector experience: critical infrastructure security consultant. To discuss a similar project, contact Agilient.