ISO 27001 is one of the most important standards for data centers. For customers, this certification is not only a mark of quality, but also a key criterion in deciding whether or not to choose a particular provider. Today, we take a closer look at what lies behind the standard and the extensive certification process together with Oliver Schwarz, Chief Information Security Officer (CISO) and Governance Risk and Compliance (GRC) Manager at EMC Home of Data.
Oliver Schwarz: Sure, gladly. As GRC Manager at EMC Home of Data, I am responsible for developing, implementing, and monitoring our information security management system (ISMS). This includes conducting risk analyses, creating and implementing security policies, and ensuring that our processes offer the ideal balance between practicality and security. I work closely with all departments to ensure that our security measures are adhered to, and as CISO, I am also the main contact person for internal and external audits. There are a number of certifications that our data center undergoes regularly/annually, for which I am responsible—ISO 27001 certification is one of the most important, but not the only one.
Oliver Schwarz: ISO 27001 offers data centers an excellent approach to information security issues such as physical security. This includes access methods, zoning concepts, and general monitoring issues. Furthermore, it is a well-known and, especially in the IT world, a recognized and valued standard on the market, which in turn creates a good basis of trust—not only nationally, but also internationally.
Oliver Schwarz: We have committed ourselves to several standards that are important to us in order to be able to offer our customers the highest quality service. In addition to ISO 27001, these include ISO 9001 (for quality management), DIN EN 50600 (a specific standard for data centers that regulates design, construction, and operation), and ISO 50001 (energy management for sustainable and efficient operation)
These standards complement each other very well and create a highly compatible and coordinated foundation for security, quality, and sustainability in our data center operations.
Oliver Schwarz: ISO 27001 certification always takes place on a three-year schedule. If you are starting from scratch, this begins with an initial certification. Since we have been ISO 27001 certified for more than 14 years, this no longer applies to us. Instead, we undergo recertification audits and surveillance audits, which are also carried out on a three-year cycle. Two surveillance audits are followed by recertification in the third year.
My role in this? In short, I make sure that we comply with and can demonstrate what we have committed to, and that we can guarantee ourselves and our customers the highest possible level of security, availability, and confidentiality.
Oliver Schwarz: Put simply, an audit is a question and answer game. Of course, there is a formal procedure with clear steps—from preparation to internal review to the actual audit. But if you reduce it to that, you are doing something fundamentally wrong, in my opinion. An “audit process” should not be started with an attitude of “Oh, the audit is coming up soon, let's see.” Rather, it is about a permanent approach that should be permanently anchored in the organization.
Oliver Schwarz: This year's audit was somewhat complex and therefore more time-consuming for two reasons: Firstly, because we had a version jump in the standard – from ISO 27001:2013 to the latest version, ISO 27001:2022.
Secondly, we included our two new data center units (MUC II including MuCon-X) in Munich and the new data center in Rosenheim (RO I) in the ISO scope. That meant quite a bit of extra work.
Oliver Schwarz: For us, this question is relatively easy to answer. We have decided not to set any boundaries. In other words, the scope is comprehensive. Or to put it another way, ISO 27001 covers all areas of the company, departments, locations, and employees.
Oliver Schwarz: The most important step is to implement a functioning ISMS that meets all the defined MUST requirements of the standard. Such an ISMS includes, among other things: a comprehensive risk analysis, various security guidelines, technical and organizational measures, internal audits, and—in my opinion—most importantly, a clear commitment from top management and a high degree of transparency toward employees, so that it doesn't just generate paperwork, but everything specified in it can also be implemented. This set of rules or ISMS is then reviewed by an independent certification body as part of external audits.
Oliver Schwarz: ISO 27001 certification is an internationally recognized “seal of approval” issued by a neutral certification body—similar to taking your car to the MOT. Our customers can therefore be sure that their data is protected by us in accordance with the highest security standards. The certification offers them a high level of confidence and can thus minimize the risk of security incidents. In addition, by working with a certified data center, our customers can also better meet their own compliance requirements. Overall, ISO 27001 certification helps to strengthen the relationships and trust between us and our customers.
Oliver Schwarz: There is only one sensible approach, in my opinion:
If you succeed, playing with standards can even be a lot of fun.
Oliver Schwarz: Anyone who goes to the trouble of obtaining ISO 27001 certification should also live by it. Those who do it just for the stamp and the certificate on the wall are better off not bothering.
Oliver Schwarz is Chief Information Security Officer (CISO) and Governance Risk and Compliance (GRC) Manager. He has held these positions at EMC Home of Data since 2021, bringing with him many years of experience in IT consulting, process and risk management, policy and compliance, and as an IT auditor and IT auditor, among other roles.
We, the EMC Home of Data team and I personally, would like to share our enthusiasm for the topics of data centers and colocation with you.
Please contact me, I look forward to hearing from you!
Elisabeth-Selbert-Str. 7 · D-80939 Munich
Tel.: 089 30 90 580-0 · hod@emc-homeofdata.de