Francesca Lucarini
October 15, 2019
ISO 27001 is about protecting information through a set of requirements that, among other methods, preserve information from unauthorized access or use. Every organization handles a variety of information with different associated risks depending on the people or the functional department to which it refers. Law firms are an example of organizations dealing with highly confidential information about employees, suppliers, contractors, and customers.
Confidential information could be personal data, R&D files, intellectual property rights, or financial deals. Some information may be disclosed to the public, while some needs to be kept confidential; some could be accessible to every member in the organization, while some needs to be restricted and within reach only for privileged users. Whatever it is, information needs to be protected. Learn how ISO 27001 certification helps in this article.
So, let’s see how ISO 27001 implementation can be helpful in protecting confidential information in any type of company, and in the next section, you’ll find some useful tips on protecting the information in law firms.
ISO 27001 is a standard that is not compulsory, but definitely advisable for law firms when talking about information protection.
Law firms handle a real treasure trove of personal and sensitive data and represent a potential target for hackers, and therefore can serve as an example of the most likely to be compromised by an attack. The implications of a legal breach could be worse for organizations operating in the legal sector than for those in other sectors, primarily because of the reputational damage being caused.
Law firms must keep their client data as safe as possible in order to preserve their clients’ trust. ISO 27001 helps them by providing security controls. We have singled out some key controls that are considered highly recommended in law firms.
Information inside an organization should be classified considering its value and level of sensitivity. Most commonly, this is according to the confidentiality.
ISO 27001 control A.8.2.1 requires an organization to ensure that information has an appropriate level of protection considering its importance. In law firms, the primary source of information includes data about clients, judges, cases, trials, and legislative changes, but there are different levels of importance and confidentiality regarding every one of them.
Client trade secrets, details on mergers and acquisitions, and attorney-client privileged information are true examples of highly confidential information that require strong security measures. In contrast, a law firm’s communication that is directed to all employees, even if classified as internal and therefore not approved for release in the public domain, could have a negative effect on just a small group of users.
Moreover, there could be information unanimously considered confidential, such as organizational changes (especially those affecting the HR department), which are not included in the organizational scheme of classification and are thereby disclosed.
Consequently, law firms are recommended to provide employees with a system categorizing all information on the basis of the level of confidentiality and the impact to the organization in case of alteration, destruction, or unauthorized disclosure of data. Different procedures about data protection should be applied to each classification level in order to safeguard proper security.
A suggested scheme of classification for law firms could include the following categories: “Public,” “Internal use,” “Restricted,” and “Confidential.”
Once information is classified, a labeling pattern should be implemented according to the classification scheme adopted.
People working inside a law firm should recognize the kind of information they handle in a clear and timely manner in order for sensitive information to be shared or kept safer.
A pattern of labeling reflecting the scheme of classification (public, internal, restricted, or confidential) could be adopted. Examples of labels could be:
A set of procedures for handling data should be implemented according to the level of confidentiality of information as identified by the classification scheme.
An organization handling highly sensitive information, such as a law firm, should adopt a set of rules to manage, archive, and use assets on the basis of the level of confidentiality. In accordance with the classification scheme suggested in the A.8.2.1 control paragraph, examples could include:
Now that we’ve seen how ISO 27001 positively impacts the protection of confidential information in law firms, think once more about the level of confidentiality of your business, and take all the steps needed to protect your sensitive information. Implementation and eventual certification against ISO 27001 is a reliable and trustworthy way to achieve your goal, so this is definitely something to think about and discuss with your executives.
For more help about handling risks when protecting confidential information in a law firm, download this free white paper: Step-by-step explanation of ISO 27001 risk management.