Omnex recommends that organizations consider a management systems’ approach versus an ad hoc approach when implementing Cybersecurity. ISO 27001 - IT Security looks at both Cybersecurity, i.e., external threats and internal threats and takes a comprehensive approach to implementing IT and Cybersecurity.
ISO 27001 adopts the High-Level Structure of IATF 16949 and ISO 14001 and can be integrated into the same management system. The differences are in the required risk analysis and vulnerability analysis and applying controls to mitigate the risk. This is where the NIST SP 800 series of standards come into play. NIST Standards are a requirement if you deal with the US Government. Omnex, who is ISO 27001 certified, is applying NIST SP 800-53 with its 256 controls. This, though a requirement from Omnex top management was also required by an important customer.