Case Study: Sydney Water

Sydney WaterMPj04033400000[1]

ISG assisted Sydney Water in designing and implementing an Information Security Management System that is compliant with the requirements of ISO27001. The new system was designed around and aligned to core critical processes of Sydney Water, enabling a focused business outcome to be achieved.

Using a business process based approach to the implementation of IT Security we assisted Sydney Water to benchmark, plan and implement improvements in their application security and the underlying IT Infrastructure used to support them. Rather than focusing on the controls layer within the organisation an implementation model was developed that placed emphasis on the effective operation of the Information Security Management System.

We supported the implementation by using leading controls embedment approaches drawn from ITIL and CobiT to assist Sydney Water to develop a series of Information Security OLAs that focused business managers around the controls that are required to be maintained to assure the secure operations of the business environments and associated technology environments on which they rely.