Technology

Banglalink renews ISO 27001 — the two things on a certificate that decide whether it means anything

A certificate covers a defined scope and comes from a body that is either accredited or not. Those two lines decide its worth, and neither is in any announcement.

Banglalink renews ISO 27001 — the two things on a certificate that decide whether it means anything

A mobile operator knows an uncomfortable amount about you: where your phone has been, whom you call, which apps wake up at night, and the national ID you handed over at the SIM counter. So when Banglalink announced it has again been certified to ISO 27001:2022, the claim is worth knowing how to read.

What the standard actually certifies

ISO 27001 is the most widely used international standard for an Information Security Management System. It does not certify a product, a firewall or a network. It certifies that an organisation has a documented, functioning system for identifying its information risks, deciding how to treat them, and demonstrating to an outside auditor that the chosen controls are genuinely in use.

The distinction matters. The standard does not say an organisation is secure. It says the organisation has a method, follows it, and can produce evidence — which is weaker than the first reading and considerably more than most companies can show.

The 2022 edition reorganised the control set and added items reflecting cloud services, threat intelligence and data leakage: the things that occupy security teams now rather than a decade ago.

The most important line on the certificate

Here is what almost no announcement mentions and what anyone evaluating such a claim should ask for first.

Every ISO 27001 certificate carries a scope statement — a sentence defining precisely which parts of the organisation were assessed. That scope can be the whole company, or it can be one data centre, one business unit, or the systems supporting a single service.

Both are legitimate and both produce an identical-looking certificate. An organisation can accurately say "we are ISO 27001 certified" when the assessment covered a fraction of what it does. Nothing improper is happening; the scope is printed on the certificate and anyone can read it. The problem is that the announcement rarely quotes it, so the reader supplies the widest interpretation.

So the first question about any certification is not whether it exists. It is what does the scope statement say, and does it include the systems holding the data you actually care about.

The second question is about the certifier. Certification bodies are themselves assessed — accredited — by national accreditation authorities, and an accredited certificate is subject to rules about auditor competence and independence that an unaccredited one is not. Anyone may print a certificate. Not everyone is accountable for having audited properly. The accreditation mark appears on the document, and its absence is informative.

What "renewed" means

Certification runs on a three-year cycle. The full audit happens at the start; the two years that follow carry lighter surveillance audits checking that the system is still operating, usually sampling rather than re-examining everything. At the end of three years comes recertification, a fuller exercise again.

So "renewed" can describe a surveillance visit or a full recertification, and the two are not equivalent. A company's own announcement will not usually distinguish them, which is reasonable — but it means the word carries less information than it appears to.

There is a further structural limit worth stating. Certification is a snapshot taken on a schedule by an auditor sampling evidence, not continuous monitoring. It establishes that controls were working on the days they were examined. Every organisation that has ever suffered a serious breach while certified was certified honestly; the certificate was never a guarantee, and reading it as one is the error.

What the auditors looked at here

According to the company the assessment covered policies, operations and institutional capability, including security governance, risk management, access controls, asset and vendor management, business-continuity planning and operational security.

In practical terms that means questions such as: who can open a subscriber's record, and is every such access logged and reviewed by someone who would notice a pattern? What happens when a contractor's laptop is lost? How quickly can billing and network services be restored after a serious incident, and when was that last actually rehearsed rather than documented?

The chief technology and information officer framed the renewal as a reaffirmation of the company's promise to protect customer data, and the operator points to staff-awareness programmes and a plan to strengthen its compliance framework.

What it says nothing about

This is the limit most worth understanding, because it is a different subject rather than a weaker version of the same one.

ISO 27001 governs how an organisation protects data. It says nothing about whether the organisation should hold that data, how long it keeps it, what it uses it for, whom it shares it with, or whether you could ask for a copy or its deletion. A company can be properly certified while retaining location history indefinitely and selling derived analytics, because none of that is a security failure. It is a privacy question, governed by separate standards and, in most countries, by law.

For a telecom operator that distinction is the whole of the public interest. The database linking a phone number to a verified national identity is valuable precisely because it is accurate, and the questions a subscriber would most want answered — what is retained, for how long, who inside the company can see it, what is handed to third parties — sit outside what this certificate addresses.

The fair conclusion

Repeated leaks of citizen data from public and private systems have made telecom databases an obvious target. A certified management system does not make a breach impossible, but it makes the unglamorous work — access reviews, vendor checks, incident drills — mandatory and inspectable, and that discipline is exactly what has been missing where leaks occurred.

In a market where most companies say "your data is safe" and offer no evidence whatsoever, an externally audited standard is a real step up. It is also a claim with two readable qualifiers on the certificate itself. Asking an operator to publish its scope statement and name its certification body is a reasonable request, cheap to satisfy, and a good test of how much the announcement was meant to convey.

Source: ISO/IEC 27001:2022, accreditation practice, certification audit cycles, Banglalink

Written by

Rakin M

Rakin M writes Tech BD’s security and privacy coverage — breaches, scams, surveillance and account safety. He is more interested in the step a reader can take this evening than in the name of the vulnerability, and says so in most of what he writes.