【GBASE Event】GBase Holds Information Security Management System Training Session

Published on 2020-09-07

From August 28 to 29, 2020, GBase successfully held its ISO 27001 Information Security Management System internal auditor training, opening a new chapter in the company’s internal training for ISO series standard internal auditors. The participants included supervisors and technical professionals from GBase’s Product Division, Engineering Technical Service Department, Business Division Solutions Department, HR & Administration Department, Operations Management Department, and Jiangsu Huaku.

▲ Pre-training Preparation

As digitalization advances, information security has increasingly become a focal point of concern. Organizations, institutions, and individuals worldwide are exploring how to safeguard information security. Information security management is especially critical and serves as the core guiding principle of security. The ISO 27001 international standard (ISO 27001:2013), issued by the International Organization for Standardization, is currently the world’s only “information security management standard” and has become the universal language for information security management, adopted by over 5,000 government agencies and renowned enterprises globally. Its approach is to address an enterprise’s information security needs through “risk assessment” and “risk management,” effectively reducing the risks the enterprise faces. Establishing an ISO 27001 Information Security Management System (ISMS) has become an essential mechanism for various organizations—especially high-tech industries, financial institutions, IT, and power sectors—to manage and reduce operational risks. ISO 27001 certification has also become a prerequisite demanded by some customers.

In November 2019, Tianjin General Data Technology Co., Ltd. obtained ISO 27001 Information Security Management System certification for the first time. Holding this ISO 27001 ISMS internal auditor corporate training is one of a series of actions to optimize and implement the system’s requirements. The course was delivered by a senior instructor from Shanghai Qingbiao Information Technology Service Co., Ltd., covering ISO 27001 ISMS requirements, 113 controls across 14 information security control domains, practical rules for information security, risk assessment and risk management, internal audits, and management reviews—providing a comprehensive overview of the knowledge system related to ISO 27001. Throughout the training, the instructor combined extensive consulting and practical experience with video case analysis to give detailed explanations and facilitate interactive exchanges on specific issues in ISMS implementation and the application of the standard in the enterprise. The aim was to help participants understand ISO 27001 requirements for information security management, become familiar with the process and methods of establishing an ISMS, and master the knowledge and skills for auditing and monitoring the ISMS.

▲ Classroom Moments

During the training, participants studied and reflected diligently, asked questions when they encountered difficulties, and discussed with the instructor how to integrate theory with work practice. After the course, everyone expressed that they had benefited greatly. Through this systematic training, they not only gained an understanding of the ISO 27001 system and standard content, but will also be able to help the company address practical information security management issues and drive the development of their respective departments’ ISMS in the future, significantly enhancing their own information security capabilities, management levels, and system audit skills. The successful completion of this ISO 27001 ISMS internal auditor training will also lay a solid foundation for information security management to support the company’s business continuity and product information security.