ISO 27001: Interview with Oliver Schwarz, CISO & GRC Manager

ISO 27001 is one of the most important standards for data centers. For customers, this certification is not only a mark of quality, but also a key criterion in deciding whether or not to choose a particular provider. Today, we take a closer look at what lies behind the standard and the extensive certification process together with Oliver Schwarz, Chief Information Security Officer (CISO) and Governance Risk and Compliance (GRC) Manager at EMC Home of Data.

 

Oliver, as GRC Manager, you are the main person responsible for compliance with standards and regulatory requirements such as ISO 27001—but that's not all. Please explain to us what your role is in our company.

 

Oliver Schwarz: Sure, gladly. As GRC Manager at EMC Home of Data, I am responsible for developing, implementing, and monitoring our information security management system (ISMS). This includes conducting risk analyses, creating and implementing security policies, and ensuring that our processes offer the ideal balance between practicality and security. I work closely with all departments to ensure that our security measures are adhered to, and as CISO, I am also the main contact person for internal and external audits. There are a number of certifications that our data center undergoes regularly/annually, for which I am responsible—ISO 27001 certification is one of the most important, but not the only one.

 

Why is the ISO 27001 standard so important in the IT industry and, therefore, for us as a data center operator?

 

Oliver Schwarz: ISO 27001 offers data centers an excellent approach to information security issues such as physical security. This includes access methods, zoning concepts, and general monitoring issues. Furthermore, it is a well-known and, especially in the IT world, a recognized and valued standard on the market, which in turn creates a good basis of trust—not only nationally, but also internationally.

 

What other standards have we committed to, and how does ISO 27001 fit in?

 

Oliver Schwarz: We have committed ourselves to several standards that are important to us in order to be able to offer our customers the highest quality service. In addition to ISO 27001, these include ISO 9001 (for quality management), DIN EN 50600 (a specific standard for data centers that regulates design, construction, and operation), and ISO 50001 (energy management for sustainable and efficient operation)

These standards complement each other very well and create a highly compatible and coordinated foundation for security, quality, and sustainability in our data center operations.

 

How often is ISO 27001 certification carried out, and what role do you play in this process?

 

Oliver Schwarz: ISO 27001 certification always takes place on a three-year schedule. If you are starting from scratch, this begins with an initial certification. Since we have been ISO 27001 certified for more than 14 years, this no longer applies to us. Instead, we undergo recertification audits and surveillance audits, which are also carried out on a three-year cycle. Two surveillance audits are followed by recertification in the third year.

My role in this? In short, I make sure that we comply with and can demonstrate what we have committed to, and that we can guarantee ourselves and our customers the highest possible level of security, availability, and confidentiality.

 

What are the key steps in the certification process?

 

Oliver Schwarz: Put simply, an audit is a question and answer game. Of course, there is a formal procedure with clear steps—from preparation to internal review to the actual audit. But if you reduce it to that, you are doing something fundamentally wrong, in my opinion. An “audit process” should not be started with an attitude of “Oh, the audit is coming up soon, let's see.” Rather, it is about a permanent approach that should be permanently anchored in the organization.

 

What challenges did you encounter during this year's certification process?

 

Oliver Schwarz: This year's audit was somewhat complex and therefore more time-consuming for two reasons: Firstly, because we had a version jump in the standard – from ISO 27001:2013 to the latest version, ISO 27001:2022.

Secondly, we included our two new data center units (MUC II including MuCon-X) in Munich and the new data center in Rosenheim (RO I) in the ISO scope. That meant quite a bit of extra work.

 

Which areas of the company does ISO 27001 cover?

 

Oliver Schwarz: For us, this question is relatively easy to answer. We have decided not to set any boundaries. In other words, the scope is comprehensive. Or to put it another way, ISO 27001 covers all areas of the company, departments, locations, and employees.

 

What are the requirements that a data center must meet in order to obtain ISO 27001 certification?

 

Oliver Schwarz: The most important step is to implement a functioning ISMS that meets all the defined MUST requirements of the standard. Such an ISMS includes, among other things: a comprehensive risk analysis, various security guidelines, technical and organizational measures, internal audits, and—in my opinion—most importantly, a clear commitment from top management and a high degree of transparency toward employees, so that it doesn't just generate paperwork, but everything specified in it can also be implemented. This set of rules or ISMS is then reviewed by an independent certification body as part of external audits.

 

What are the benefits of ISO 27001 certification for our customers?

 

Oliver Schwarz: ISO 27001 certification is an internationally recognized “seal of approval” issued by a neutral certification body—similar to taking your car to the MOT. Our customers can therefore be sure that their data is protected by us in accordance with the highest security standards. The certification offers them a high level of confidence and can thus minimize the risk of security incidents. In addition, by working with a certified data center, our customers can also better meet their own compliance requirements. Overall, ISO 27001 certification helps to strengthen the relationships and trust between us and our customers.

 

How do you ensure that the requirements of ISO 27001 are continuously met?

 

Oliver Schwarz: There is only one sensible approach, in my opinion:

  • Keep a constant eye on the issue and work continuously to improve.
  • Raise awareness among all colleagues as to why and how we do these things.
  • Maintain regular and open communication with top management.

If you succeed, playing with standards can even be a lot of fun.

 

Is there anything else you would like to share with our readers about ISO 27001 certification?

 

Oliver Schwarz: Anyone who goes to the trouble of obtaining ISO 27001 certification should also live by it. Those who do it just for the stamp and the certificate on the wall are better off not bothering.

 

Thank you very much for the interview and the valuable insights, Oliver!

 

About Oliver Schwarz

Oliver Schwarz is Chief Information Security Officer (CISO) and Governance Risk and Compliance (GRC) Manager. He has held these positions at EMC Home of Data since 2021, bringing with him many years of experience in IT consulting, process and risk management, policy and compliance, and as an IT auditor and IT auditor, among other roles.

Go back

We will be pleased to advise you.

Bernhard Huter
CEO

We, the EMC Home of Data team and I personally, would like to share our enthusiasm for the topics of data centers and colocation with you.

Please contact me, I look forward to hearing from you!

‍ 

EMC Home of Data GmbH

Elisabeth-Selbert-Str. 7 · D-80939 Munich
Tel.: 089 30 90 580-0 ·