Log4Shell is a critical vulnerability in Log4j. Frank Blaauw shares how Researchable, as an ISO27001-certified organisation, is dealing with it.
In brief
- Log4Shell is a critical vulnerability in the logging library Log4j that lets someone execute code remotely in Java applications.
- Thanks to our ISO27001 asset management, we quickly identified every system that could be vulnerable.
- We followed our incident management process, mapped out the affected suppliers and scheduled repeated checks.
- ISO27001 is about continuous improvement: we are optimising our system overviews based on what this incident taught us.
Log4Shell is a critical vulnerability in the widely used logging tool Log4j. This problem affects many companies, both through vulnerabilities in their own software and in that of their suppliers. At Researchable we are ISO27001-certified, and I would like to share how we are dealing with the Log4Shell vulnerability and how ISO27001 has helped us do so.
What is the problem?
A serious vulnerability has been found in the popular logging library Log4j, which is widely used for logging in Java applications. It allows an unauthorised person to execute code remotely in the Java application that uses this library. Because of its widespread use in servers and desktop applications, the announced CVEs (a database of public information security issues) have a large impact.
Asset management and ISO27001
An important element of ISO27001 is asset management of the systems you use. These range from servers hosted on AWS to email-sending services. Keeping such a list of all the systems in use is quite a job, but we are only now seeing the real benefits. Thanks to this list, we could easily identify every system that could be vulnerable.
Incident management process
Based on the system list, we followed our incident management process to determine the impact of this CVE on our services and suppliers. We also made an overview of all suppliers that could be affected. Because the news about this keeps changing, we also scheduled repeated checks to make sure all systems in use are secure.
What is ISO27001
- ISO27001 is an international standard that sets requirements for an information security management system (ISMS).
- It follows a Plan-Do-Check-Act cycle in which all information in the ISO27001 ISMS is continuously evaluated and updated.
- It helps organisations manage their information security in a structured way.
Relevance becomes clear
ISO27001 offers excellent processes whose relevance sometimes only becomes clear during incidents like the Log4Shell vulnerability. Through this incident we saw the value of our asset management system, but we also noticed that it took too long to distinguish between self-hosted and cloud-hosted services, and services used only for development (which, based on this CVE, can still pose a security risk).
Continuous improvement
We have learned from this vulnerability and are working on optimising our process to produce better overviews of our systems. We have already planned several objectives to create better overviews of these systems. The foundation of ISO27001 is continuous improvement, which is also a core value of Researchable.
ISO27001 offers excellent processes whose relevance sometimes only becomes clear during incidents like the Log4Shell vulnerability.
Frank Blaauw
Frequently asked questions
What is the Log4Shell vulnerability?
Log4Shell is a serious vulnerability in Log4j, a widely used logging library for Java applications. It allows an unauthorised person to execute code remotely in the application that uses the library.
Why does Log4Shell have such a large impact?
Log4j is deployed widely across servers and desktop applications. Because of that broad use, the announced CVEs affect many companies, both through their own software and through that of their suppliers.
How does ISO27001 help when responding to a vulnerability like Log4Shell?
ISO27001 requires asset management: an up-to-date list of all systems in use. With that list you quickly identify which systems could be vulnerable, and through the incident management process you determine the impact on your services and suppliers.
How did Researchable deal with Log4Shell?
We used our ISO27001 system list to identify vulnerable systems and followed our incident management process to determine the impact. We mapped out the affected suppliers and scheduled repeated checks, because the news about this keeps changing.
What is ISO27001?
ISO27001 is an international standard that sets requirements for an information security management system (ISMS). It follows a Plan-Do-Check-Act cycle in which all information is continuously evaluated and updated, so organisations manage their information security in a structured way.





