Skip to main content
← Projects

Rainforest Foundation of Norway Data Security

Assessed human resources and finance aspects related to data risks for the Rainforest Foundation of Norway's partners in Indonesia using ISO 27005 standards, including an assessment of risk identification, risk estimation, and risk evaluation.

Background

Information/data security is one of the most dynamic and fast-changing fields. Security threats are constantly evolving, new vulnerabilities are being discovered, and new exploits are being created to target those vulnerabilities. In the last week of November 2020, Hatfield Indonesia (PTHI) received the Terms of Reference (TOR) document from Rainforest Foundation Norway (RFN).

Hatfield Indonesia in conjunction with Dala Institute worked to strengthen data security capacity of Rainforest Foundation Norway (RFN)'s partner organisations in Indonesia. Specifically, we assessed the partners' risks and needs for data security capacity development including but not limited to data storage and data sharing systems and tools.

 

RFN

Approach

The risk assessment approach procedures for this work were borrowed from the safety world, where well-assessed methodologies for safety-related risk assessment exist. On this project, we used the ISO 27005 standard. It provided guidance on information security risk management processes needed for the implementation of an effective information security management system (ISMS). Though this standard is considered a risk management standard, a significant portion of it deals with risk assessments, which are of course a key part of a risk management programme. ISO 27005 has three steps for the section dealing with risk assessment: Risk Identification, Risk Estimation, and Risk Evaluation.