NHS Professionals achieves ISO 27001 certification and improves their infosec management
Download PDFThe Challenge
As a result of the nature of their business, processing staff, client and candidate personal data means information security is critical. As such the information security management system underpinning the business is key.
When NHS Professionals got in touch with ISMS.online they had two objectives: achieve UKAS certified ISO 27001 quickly and improve their ongoing management of information security. These key business objectives were at the heart of the ISO implementation project and the driving force for achieving certification in such a short time.
How did NHS Professionals approach infosec before using ISMS.online?
NHS Professionals had held ISO 9001 for 7 years and were already compliant with both the NHS Data Security Protection Toolkit (DSPT)and GDPR. Like many organisations, they were documenting their InfoSec in Word and Excel and saving their policies on shared drives.
As we often see with organisations using these types of solutions, it is hard to keep them up to date for one standard. So, when you have multiple standards or regulations to follow, the whole system can fall over or become very expensive to maintain. It can also result in practical challenges around collaboration, version control, policy approval and policy sharing. All that can ultimately cause noncompliance and increase business risk rather than reduce it.
“Adding ISO 27001 certification could have resulted in duplicated efforts and policies increasing cost and adding risks, so we sought advice from a consultant who indicated that ISMS.online would help streamline our mature processes and reduce the time taken to certification.”
IT Director, NHS Professionals