Rhand Leal
March 26, 2018
Update 2022-03-16.
“The human factor is the weakest link in the security.” How many times have we already heard this sentence? How many stories have we already heard about security incidents caused by human failure or inaction?
In an effort to minimize this situation, organizations all around the world have been working hard to make their employees and contractors aware of the importance of protecting information, and to prepare them to handle attempted attacks and incidents when they arise. But, what if the wrong person is allowed to enter the organization? What if a person you think is competent for the job is, in fact, not that competent? The best training and awareness campaigns won’t help you with that.
In this article, you will see how ISO 27001, the leading ISO standard for information security management, addresses human resources security before employment, and how its practices can help your organization to put in place the right people for the job. Learn here more about ISO 27001 background checks.
In terms of information security, we can basically summarize this answer in two words: trust and competence.
When an organization decides to hire someone, this person will interact with other people’s information, either from other employees, partners, or customers. It’s essential to ensure that you can trust this person to handle and protect information.
Following trust, when an organization hires, it is seeking to find the most capable people to perform specific activities in order to achieve its business objectives, so verifying competence is essential. (See also: How to learn about ISO 27001 and BS 25999-2.)
When hiring new employees, a company needs to show due diligence by implementing ISO 27001 background checks in order to find trustworthy and competent people.
For example, to implement a secure network, it is expected for a person to have solid knowledge and experience in this issue. If a potential employee, i.e., a candidate for the position, does not have such competences, he/she shouldn’t be considered for that position, because the organization may be considered liable in case of problems or incidents.
To ensure that these aspects can be fulfilled for information security, an ISO 27001 background check could include:
It is important to note that background checks must be performed:
In cases where the background checks are performed by a contractor on behalf of the organization, an agreement should be defined between the organization and the contractor to ensure that the contractor will perform the procedure and communicate any situations that raise doubts or concerns.
Because ISO 27001 background checks involve the gathering of information that may be considered private or intimate, or may allow the personal identification of a person, some issues must be considered to prevent the organization from being subject to legal action:
Hiring someone to work for your organization may be the most critical aspect of the business, because no matter how good your processes, equipment, resources, and systems are, all of them will be in the hands of those you will hire. In the wrong hands, even the best tool can be useless or used to cause damage.
By performing background checks according to ISO 27001 requirements, you can minimize the risks of poor performance and the compromising of critical information from the organization.
Learn more about human resources security in this free online training: ISO 27001 Foundations Online Course.