Agilient revised an international data centre operator’s information security management system for re-certification and built an integrated management system for quality, environment and information security to reduce duplicated compliance effort.

THE CHALLENGE

An international data centre operator runs a major facility in Australia serving telecommunications, cloud, financial and government customers. Certified management systems for security, quality and environmental practice are central to its reputation. After an internal restructure, and ahead of a re-certification audit, a gap analysis of its information security management system (ISMS) showed that many policies and procedures needed to be re-drafted or substantially revised to meet ISO/IEC 27001. At the same time, its ISO 9001 quality and ISO 14001 environmental systems were run as standalone frameworks, which duplicated effort and added administrative overhead. The operator needed to bring the ISMS into line quickly and wanted to use the opportunity to build an integrated management system.

OUR APPROACH

Agilient delivered a multi-phased program with two workstreams running in parallel. For the ISMS, consultants systematically revised the required documentation, working with stakeholders to re-draft the Statement of Applicability, the information security risk assessment and supplier relationship policies. They developed new procedures for secure work areas and data backups and updated other policies to reflect the new organisational structure. Agilient ran a workshop to train staff on the new documentation, conducted a full internal audit of the revised ISMS and supported the operator during the external re-certification audit. In the second workstream, Agilient designed the integrated management system, using existing documentation to build common elements such as management responsibility, document control and internal audit, then developing the specific requirements of the revised ISO 9001 and ISO 14001 standards under the Annex SL structure.

THE OUTCOME

The operator passed its re-certification audit and gained a single, streamlined framework for managing risk and compliance.

Related services: security audit services, protective security and PSPF consulting, security awareness training. Sector experience: critical infrastructure security consultant. To discuss a similar project, contact Agilient.