{"id":15437,"date":"2024-09-16T14:00:00","date_gmt":"2024-09-16T12:00:00","guid":{"rendered":"https:\/\/oberender.com\/unkategorisiert\/information-security-part-5-further-building-blocks\/"},"modified":"2024-10-07T12:24:16","modified_gmt":"2024-10-07T10:24:16","slug":"information-security-part-5-further-building-blocks","status":"publish","type":"post","link":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/","title":{"rendered":"Information security Part 5 &#8211; Further building blocks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">As mentioned in the first article, the considerations in the previous episodes are only superficial.\nBehind some of the aspects and concepts mentioned are more complex challenges for you, which we will be happy to work out with you and support you in implementing. <\/p>\n\n<p class=\"wp-block-paragraph\">In this final episode, we would like to explain two important topics and aspects: employee awareness and supply chain control.<\/p>\n\n<h3 class=\"wp-block-heading\" id=\"h-mitarbeiteraufmerksamkeit\">Employee attention  <\/h3>\n\n<p class=\"wp-block-paragraph\">Those sitting in front of the computer are of course a &#8220;weak point&#8221; in the system.\nThe factors that lead to this are manifold.\nA lack of digital skills, poor equipment with IT tools, a lack of education and training and also a work overload are just some of the possible triggers for a security incident.  <\/p>\n\n<p class=\"wp-block-paragraph\">The digital identities of your company&#8217;s employees are a particular focus for attackers.\nIt&#8217;s not for nothing that the saying goes &#8220;Nowadays, hackers don&#8217;t hack, they log in!&#8221; <\/p>\n\n<p class=\"wp-block-paragraph\">Special attention should therefore be paid to this area.\nIn our view, two tasks should be particularly emphasized. <\/p>\n\n<h4 class=\"wp-block-heading\" id=\"h-ausbilden-trainieren-und-zuhoren\">Educate\/train and listen<\/h4>\n\n<p class=\"wp-block-paragraph\">You can certainly imagine what &#8220;educate\/train&#8221; means.\nHowever, the second point &#8220;Listening&#8221; is just as important.\nCreate structures in which attentive employees can submit reports without fear, which are taken seriously and dealt with promptly.  <\/p>\n\n<p class=\"wp-block-paragraph\">Then you reduce the risk that a member of your team who wants to inform the helpdesk about a suspected infection on their computer will be told that this cannot be the case and that they should simply restart the computer.<\/p>\n\n<p class=\"wp-block-paragraph\">In this context, the Anglo-Saxon term &#8220;awareness&#8221; is always associated with the person affected.\nHowever, in the context of information security, this is a dichotomous concept and includes those who should and can take care of the incident. <\/p>\n\n<p class=\"wp-block-paragraph\">The education and training can be implemented in a variety of ways.\nCombine several tools, e.g. regular training and simulations (e.g. phishing campaigns, pentests, communication training for IT). <\/p>\n\n<h3 class=\"wp-block-heading\" id=\"h-lieferkettenkontrolle\">Supply chain control<\/h3>\n\n<p class=\"wp-block-paragraph\">Admittedly, this is a somewhat loaded word and it has to do with the &#8211; attention word worm!\n&#8211; Supply Chain Due Diligence Act.\nBut that&#8217;s not the point here.  <\/p>\n\n<p class=\"wp-block-paragraph\">The consideration of supply chains also plays a role in the area of information security and includes tangible items such as computers and other components and intangible items such as IT services and software.\nAll of this penetrates the virtual perimeter of your company from the outside and influences your security situation. <\/p>\n\n<p class=\"wp-block-paragraph\">Some measures are therefore necessary here to complete and strengthen your information security concept.<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Hardware: <\/strong>Buy from trustworthy sources, especially if you are buying refurbished goods.\nTest the goods extensively before you use them <\/li>\n\n\n\n<li><strong>Software:<\/strong> Particularly in the area of industry-specific software, it is advisable to take a close look at the product, as business-critical processes are mapped here, where a loss event has a major impact.\nWe would therefore recommend that you take information security criteria into account when selecting a product.\nHow is the system operated?\nHow do you log in?\nWhat does maintenance look like?\nCan the manufacturer provide an SBOM (Software Bills of Material) to support your ISMS (synchronized with the maintenance and development cycle)?\nThis is a machine-readable list of components and built-in third-party libraries with their version statuses.\nThis allows weak points to be identified quickly.\nYou should therefore also consider your procurement processes in the name of information security.        <\/li>\n\n\n\n<li><strong>IT services<\/strong>: If you purchase IT services, there are several tasks for you.\nNo matter what form of service you purchase, define the aspects of your ISMS that the contractor should contractually observe.\nThis will include the form of service, communication structures and necessary security measures that you negotiate with the service provider.\nThere are templates that can be used for this.\nThe best known are the basic and system contracts for public clients and the supplementary contract conditions for the procurement of information technology provided by the BSI.\nHowever, please check them carefully and adapt them to your own circumstances.     <\/li>\n\n\n\n<li>And finally: <strong>Audit your service provider! <\/strong>If the contractor has a security certificate (e.g. to ISO27001), ask them to show you the basics!\nAfter all, it&#8217;s your risk! <\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">This brings us to the end of this short blog series.\nWe hope we have been able to take you on a journey through information security management that is worth reading and look forward to hearing from you. <\/p>\n\n<h3 class=\"wp-block-heading\" id=\"h-wie-geht-es-jetzt-weiter\">What happens now?  <\/h3>\n\n<p class=\"wp-block-paragraph\">We would be happy to carry out a <strong>cyber risk check<\/strong> with you for an initial assessment.\nA first step in the right direction and the basis for your information security.\nYou can find more information <a href=\"https:\/\/oberender.com\/en\/competences\/operational-management\/digital-health-in-healthcare\/cyber-risk-check\/\">here<\/a>.  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the last part of the &#8220;Information security&#8221; blog series, we will look at the building blocks of employee awareness and supply chain control.<\/p>\n","protected":false},"author":5,"featured_media":15366,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[62,220,64],"tags":[152,223,148,222,117],"class_list":["post-15437","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en","category-data-security","category-digitisation","tag-consultant","tag-cyber-security-en","tag-hospital","tag-information-security","tag-public-health"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.6.1 (Yoast SEO v27.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Information security Part 5 - Further building blocks - Oberender AG<\/title>\n<meta name=\"description\" content=\"Employee awareness and supply chain control are two important aspects of information security\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Information security Part 5 - Further building blocks - Oberender AG\" \/>\n<meta property=\"og:description\" content=\"Employee awareness and supply chain control are two important aspects of information security\" \/>\n<meta property=\"og:url\" content=\"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/\" \/>\n<meta property=\"og:site_name\" content=\"Oberender AG\" \/>\n<meta property=\"article:published_time\" content=\"2024-09-16T12:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-10-07T10:24:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/oberender.com\/wp-content\/uploads\/iStock-1329268006-1024x576.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"576\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ursula Lauterbach\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ursula Lauterbach\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/\"},\"author\":{\"name\":\"Ursula Lauterbach\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#\\\/schema\\\/person\\\/6d858500dcc179abc6e781d3d95329b3\"},\"headline\":\"Information security Part 5 &#8211; Further building blocks\",\"datePublished\":\"2024-09-16T12:00:00+00:00\",\"dateModified\":\"2024-10-07T10:24:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/\"},\"wordCount\":778,\"publisher\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/oberender.com\\\/wp-content\\\/uploads\\\/iStock-1329268006.jpg\",\"keywords\":[\"Consultant\",\"cyber-security\",\"Hospital\",\"Information security\",\"Public Health\"],\"articleSection\":[\"Blog\",\"Data security\",\"Digitisation\"],\"inLanguage\":\"en-US\",\"copyrightYear\":\"2024\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/\",\"url\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/\",\"name\":\"Information security Part 5 - Further building blocks - Oberender AG\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/oberender.com\\\/wp-content\\\/uploads\\\/iStock-1329268006.jpg\",\"datePublished\":\"2024-09-16T12:00:00+00:00\",\"dateModified\":\"2024-10-07T10:24:16+00:00\",\"description\":\"Employee awareness and supply chain control are two important aspects of information security\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/oberender.com\\\/wp-content\\\/uploads\\\/iStock-1329268006.jpg\",\"contentUrl\":\"https:\\\/\\\/oberender.com\\\/wp-content\\\/uploads\\\/iStock-1329268006.jpg\",\"width\":2309,\"height\":1299,\"caption\":\"Digital background depicting innovative technologies in security systems, data protection Internet technologies\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/blog-en\\\/information-security-part-5-further-building-blocks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/oberender.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Information security Part 5 &#8211; Further building blocks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/oberender.com\\\/en\\\/\",\"name\":\"Oberender AG\",\"description\":\"Ihr Partner im Klinikmanagement.\",\"publisher\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/oberender.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#organization\",\"name\":\"Oberender AG\",\"url\":\"https:\\\/\\\/oberender.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/oberender.com\\\/wp-content\\\/uploads\\\/171218_Oberender_RGB.png\",\"contentUrl\":\"https:\\\/\\\/oberender.com\\\/wp-content\\\/uploads\\\/171218_Oberender_RGB.png\",\"width\":769,\"height\":186,\"caption\":\"Oberender AG\"},\"image\":{\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/oberender-ag\\\/\",\"https:\\\/\\\/www.xing.com\\\/pages\\\/oberenderag\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/oberender.com\\\/en\\\/#\\\/schema\\\/person\\\/6d858500dcc179abc6e781d3d95329b3\",\"name\":\"Ursula Lauterbach\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Information security Part 5 - Further building blocks - Oberender AG","description":"Employee awareness and supply chain control are two important aspects of information security","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/","og_locale":"en_US","og_type":"article","og_title":"Information security Part 5 - Further building blocks - Oberender AG","og_description":"Employee awareness and supply chain control are two important aspects of information security","og_url":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/","og_site_name":"Oberender AG","article_published_time":"2024-09-16T12:00:00+00:00","article_modified_time":"2024-10-07T10:24:16+00:00","og_image":[{"width":1024,"height":576,"url":"https:\/\/oberender.com\/wp-content\/uploads\/iStock-1329268006-1024x576.jpg","type":"image\/jpeg"}],"author":"Ursula Lauterbach","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ursula Lauterbach","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/#article","isPartOf":{"@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/"},"author":{"name":"Ursula Lauterbach","@id":"https:\/\/oberender.com\/en\/#\/schema\/person\/6d858500dcc179abc6e781d3d95329b3"},"headline":"Information security Part 5 &#8211; Further building blocks","datePublished":"2024-09-16T12:00:00+00:00","dateModified":"2024-10-07T10:24:16+00:00","mainEntityOfPage":{"@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/"},"wordCount":778,"publisher":{"@id":"https:\/\/oberender.com\/en\/#organization"},"image":{"@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/#primaryimage"},"thumbnailUrl":"https:\/\/oberender.com\/wp-content\/uploads\/iStock-1329268006.jpg","keywords":["Consultant","cyber-security","Hospital","Information security","Public Health"],"articleSection":["Blog","Data security","Digitisation"],"inLanguage":"en-US","copyrightYear":"2024","copyrightHolder":{"@id":"https:\/\/oberender.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/","url":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/","name":"Information security Part 5 - Further building blocks - Oberender AG","isPartOf":{"@id":"https:\/\/oberender.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/#primaryimage"},"image":{"@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/#primaryimage"},"thumbnailUrl":"https:\/\/oberender.com\/wp-content\/uploads\/iStock-1329268006.jpg","datePublished":"2024-09-16T12:00:00+00:00","dateModified":"2024-10-07T10:24:16+00:00","description":"Employee awareness and supply chain control are two important aspects of information security","breadcrumb":{"@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/#primaryimage","url":"https:\/\/oberender.com\/wp-content\/uploads\/iStock-1329268006.jpg","contentUrl":"https:\/\/oberender.com\/wp-content\/uploads\/iStock-1329268006.jpg","width":2309,"height":1299,"caption":"Digital background depicting innovative technologies in security systems, data protection Internet technologies"},{"@type":"BreadcrumbList","@id":"https:\/\/oberender.com\/en\/blog-en\/information-security-part-5-further-building-blocks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/oberender.com\/en\/"},{"@type":"ListItem","position":2,"name":"Information security Part 5 &#8211; Further building blocks"}]},{"@type":"WebSite","@id":"https:\/\/oberender.com\/en\/#website","url":"https:\/\/oberender.com\/en\/","name":"Oberender AG","description":"Ihr Partner im Klinikmanagement.","publisher":{"@id":"https:\/\/oberender.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/oberender.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/oberender.com\/en\/#organization","name":"Oberender AG","url":"https:\/\/oberender.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/oberender.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/oberender.com\/wp-content\/uploads\/171218_Oberender_RGB.png","contentUrl":"https:\/\/oberender.com\/wp-content\/uploads\/171218_Oberender_RGB.png","width":769,"height":186,"caption":"Oberender AG"},"image":{"@id":"https:\/\/oberender.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/oberender-ag\/","https:\/\/www.xing.com\/pages\/oberenderag"]},{"@type":"Person","@id":"https:\/\/oberender.com\/en\/#\/schema\/person\/6d858500dcc179abc6e781d3d95329b3","name":"Ursula Lauterbach"}]}},"_links":{"self":[{"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/posts\/15437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/comments?post=15437"}],"version-history":[{"count":0,"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/posts\/15437\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/media\/15366"}],"wp:attachment":[{"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/media?parent=15437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/categories?post=15437"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oberender.com\/en\/wp-json\/wp\/v2\/tags?post=15437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}