The 1993 film Jurassic Park presents a noteworthy story from an information security perspective.
The film is from 1993. Nevertheless, if John Hammond had properly implemented the ISO/IEC 27001:2022 Information Security Management System within InGen, a significant portion of what happened could have been controlled from the outset.
When viewed through the eyes of an auditor, it becomes apparent that many events are directly related to information security.
- During the storm, even if the park had not yet opened, sufficient and competent personnel would have been present. This situation can be linked to Clause 5.3 and Annex A 5.2.
- For a park located in a tropical region, potential adverse events, including environmental risks, would have been assessed. This assessment would have been addressed under Clause 6.1.2. The necessary measures for serious risks would also be determined under Section 6.1.3. In fact, from the outset, these conditions would be addressed under external factors in accordance with Sections 4.1 and 6.1.1.
- The necessary measures would have been taken for any adverse events that could occur as the storm approached. This issue can be linked to Appendix A 5.29 and 5.30.
- Work would be carried out on recurring, i.e. systematic, problems with the velociraptors. This situation could be assessed under Article 10.1.
- Dennis Nedry could not produce malicious software and upload it to the system. This issue can be linked to Appendix A 5.3.
- The software would undergo the necessary tests before being loaded into the system. These tests would be conducted under Annex A 8.29. Any impact of the tests on the live system would also be prevented under Annex A 8.31.
- The malicious code he wrote would be detected by advanced anti-malware software. This situation could be linked to Annex A 8.7.
- When the system was affected by a storm or virus attack, backup systems would be activated. This structure can be linked to Annex A 7.5, 8.13 and 8.14.
- So much time would not be lost in resolving the issue via backup systems. This issue can be addressed under Annex A 5.9.
- Access would be easier when a hard reset of the system was required. This situation can be linked to Appendix A 7.8.
- Appendix A 5.35 independent review of information security, Appendix A 8.2 privileged access rights, Appendix A 8.9 configuration management, and Appendix A 8.19 software installation on operating systems can be considered along with many other items.
Although Jurassic Park is a fictional story, the vulnerabilities seen throughout the film clearly demonstrate how information security touches on such a broad area within an organisation’s structure. Each of the topics, such as personnel competence, risk assessment, software testing, combating malicious software, backup structure, and access management, has a direct impact on the organisation’s operations and continuity.
The Information Security Management System is a management structure that enables the organisation to identify its vulnerabilities, protects its critical processes, and determines what should be done, by whom, and in what order in the event of a disruption. The items included in this area are based on the concrete needs that arise after vulnerabilities, interruptions, and losses have been experienced. Each addresses specific risks observed in corporate operations. Therefore, information security should be considered one of the fundamental management issues affecting organisational order, continuity, and decision-making processes.
Prepared by: Cenk Erim Tezel