EFFECTIVENESS OF ISO 27001, AS AN INFORMATION SECURITY MANAGEMENT SYSTEM: AN ANALYTICAL STUDY OF FINANCIAL ASPECTS.
Naveen Sharma, Prabir Kumar Dash
Abstract
Naveen Sharma, Prabir Kumar Dash
Abstract
Effectiveness of ISO 27001 as an information security system is a measure of the expectation satisfaction level based on the organizational expectations prior to implementation of ISO 27001 and the actual results obtained after certification. Thus, effectiveness focuses on how well objectives have been achieved rather than how well processes have been followed. The effectiveness of ISO 27001 is in preventing or minimizing the exposure to information security incidents in the real world. In a scenario where there has been so much investment in adopting the framework and subsequent certification resulting in high levels of stakeholder assurance, the focus is to identifying the areas where it is effective. But more importantly, it also focus on the areas where there are gaps, leading to information security risks and/or an incident even in a situation where the framework is adhered to and certification against it exists. Companies that have ISO 27001 certification and audits gain an improved risk based approach to information security management through an ongoing process of risk assessment and risk mitigation, which helps them to adequately prioritize the implementation of countermeasures, and strengthen their security posture through the ISO rigorous testing. Organizations are then able to demonstrate that they have well internal controls over financial processes, and, more importantly, they can help mitigate information security risks by operating under one system rather than two. This approach can complement the Plan, Do, Check, Act (PDCA) process, which is a widely accepted system to drive continual improvement. The analysis results support organizations and security managers at identifying systems they can use to achieve greater efficiency in the information security management process.
OpenAlex reports 10 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Effectiveness of ISO 27001 as an information security system is a measure of the expectation satisfaction level based on the organizational expectations prior to implementation of ISO 27001 and the actual results obtained after certification. Thus, effectiveness focuses on how well objectives have been achieved rather than how well processes have been followed. The effectiveness of ISO 27001 is in preventing or minimizing the exposure to information security incidents in the real world. In a scenario where there has been so much investment in adopting the framework and subsequent certification resulting in high levels of stakeholder assurance, the focus is to identifying the areas where it is effective. But more importantly, it also focus on the areas where there are gaps, leading to information security risks and/or an incident even in a situation where the framework is adhered to and certification against it exists. Companies that have ISO 27001 certification and audits gain an improved risk based approach to information security management through an ongoing process of risk assessment and risk mitigation, which helps them to adequately prioritize the implementation of countermeasures, and strengthen their security posture through the ISO rigorous testing. Organizations are then able to demonstrate that they have well internal controls over financial processes, and, more importantly, they can help mitigate information security risks by operating under one system rather than two. This approach can complement the Plan, Do, Check, Act (PDCA) process, which is a widely accepted system to drive continual improvement. The analysis results support organizations and security managers at identifying systems they can use to achieve greater efficiency in the information security management process.
Key concepts: Information security management system, ITIL security management, Information security management, Information security standards, Information security, Risk analysis (engineering), Certification, Business