2013RePEc: Research Papers in EconomicsRequires access

Integration possibilities of ISO 9001:2008 quality management system with ISO 27001:2010 information security management system

Josip Britvić, Anita Prelas Kovačević, Monika Cingel

Open publisher page 3 citations

Abstract

The requirements of customers, users of services and actions of competitors require companies to constantly raise the level of quality of products and / or services as well as the quality level and functioning of organization. Other requirements like those arising from legislation, requirements of local communities and environment also require organizations to adapt. To help organizations meet all these requirements they can use existing tools such as ISO 9001, ISO 14001, ISO 27001 and other standards. By integrating multiple ISO standards into one integrated system it's possible to meet a wider range of requirements. The paper analyzes the possibility to integrate the ISO 9001:2008 quality management system with ISO 27001:2010 Information Security Management System and application possibilities of the integrated system in practice. Organization with implemented quality management system proves that its quality management system complies with the requirements of ISO 9001:2008. Thus the risk of uncertainty in customers towards the quality of products or services is reduced, so organizations are increasingly seeking to obtain this certification. As some organizations require not only the quality of products and services, but also the safety of these, ISO 9001:2008 is a great start for organizations towards implementation of other ISO standards, in this case the ISO 27001:2010. The purpose of ISO 27001:2010 is to show customers that information security in the organization is carried out in the best possible way and to gain their trust. Therefore we can say that the ISO 27001:2010 means for information security the same thing as ISO 9001:2008 means for quality management system. In this paper will be shown how to implement the standards individually and whether there is the possibility of integrating these standards.

Open-access reader

About this research paper

What this paper is about

The requirements of customers, users of services and actions of competitors require companies to constantly raise the level of quality of products and / or services as well as the quality level and functioning of organization. Other requirements like those arising from legislation, requirements of local communities and environment also require organizations to adapt. To help organizations meet all these requirements they can use existing tools such as ISO 9001, ISO 14001, ISO 27001 and other standards. By integrating multiple ISO standards into one integrated system it's possible to meet a wider range of requirements. The paper analyzes the possibility to integrate the ISO 9001:2008 quality management system with ISO 27001:2010 Information Security Management System and application possibilities of the integrated system in practice. Organization with implemented quality management system proves that its quality management system complies with the requirements of ISO 9001:2008. Thus the risk of uncertainty in customers towards the quality of products or services is reduced, so organizations are increasingly seeking to obtain this certification. As some organizations require not only the quality of products and services, but also the safety of these, ISO 9001:2008 is a great start for organizations towards implementation of other ISO standards, in this case the ISO 27001:2010. The purpose of ISO 27001:2010 is to show customers that information security in the organization is carried out in the best possible way and to gain their trust. Therefore we can say that the ISO 27001:2010 means for information security the same thing as ISO 9001:2008 means for quality management system. In this paper will be shown how to implement the standards individually and whether there is the possibility of integrating these standards.

Why it matters

OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The requirements of customers, users of services and actions of competitors require companies to constantly raise the level of quality of products and / or services as well as the quality level and functioning of organization. Other requirements like those arising from legislation, requirements of local communities and environment also require organizations to adapt. To help organizations meet all these requirements they can use existing tools such as ISO 9001, ISO 14001, ISO 27001 and other standards. By integrating multiple ISO standards into one integrated system it's possible to meet a wider range of requirements. The paper analyzes the possibility to integrate the ISO 9001:2008 quality management system with ISO 27001:2010 Information Security Management System and application possibilities of the integrated system in practice. Organization with implemented quality management system proves that its quality management system complies with the requirements of ISO 9001:2008. Thus the risk of uncertainty in customers towards the quality of products or services is reduced, so organizations are increasingly seeking to obtain this certification. As some organizations require not only the quality of products and services, but also the safety of these, ISO 9001:2008 is a great start for organizations towards implementation of other ISO standards, in this case the ISO 27001:2010. The purpose of ISO 27001:2010 is to show customers that information security in the organization is carried out in the best possible way and to gain their trust. Therefore we can say that the ISO 27001:2010 means for information security the same thing as ISO 9001:2008 means for quality management system. In this paper will be shown how to implement the standards individually and whether there is the possibility of integrating these standards.

Key concepts: Information security management system, ITIL security management, Quality management system, Quality of analytical results, Information Technology Infrastructure Library, Certification, Business, Process management

Related papers

Back to paper searchBrowse research topicsOriginal source
Integration possibilities of ISO 9001:2008 quality management system with ISO 27001:2010 information security management system — Research Paper | ScholarLens