2012The Far East Journal of Psychology and BusinessRequires access

EFFECTIVENESS OF ISO 27001, AS AN INFORMATION SECURITY MANAGEMENT SYSTEM: AN ANALYTICAL STUDY OF FINANCIAL ASPECTS.

Naveen Sharma, Prabir Kumar Dash

Open publisher page 10 citations

Abstract

Effectiveness of ISO 27001 as an information security system is a measure of the expectation satisfaction level based on the organizational expectations prior to implementation of ISO 27001 and the actual results obtained after certification. Thus, effectiveness focuses on how well objectives have been achieved rather than how well processes have been followed. The effectiveness of ISO 27001 is in preventing or minimizing the exposure to information security incidents in the real world. In a scenario where there has been so much investment in adopting the framework and subsequent certification resulting in high levels of stakeholder assurance, the focus is to identifying the areas where it is effective. But more importantly, it also focus on the areas where there are gaps, leading to information security risks and/or an incident even in a situation where the framework is adhered to and certification against it exists. Companies that have ISO 27001 certification and audits gain an improved risk based approach to information security management through an ongoing process of risk assessment and risk mitigation, which helps them to adequately prioritize the implementation of countermeasures, and strengthen their security posture through the ISO rigorous testing. Organizations are then able to demonstrate that they have well internal controls over financial processes, and, more importantly, they can help mitigate information security risks by operating under one system rather than two. This approach can complement the Plan, Do, Check, Act (PDCA) process, which is a widely accepted system to drive continual improvement. The analysis results support organizations and security managers at identifying systems they can use to achieve greater efficiency in the information security management process.

About this research paper

What this paper is about

Effectiveness of ISO 27001 as an information security system is a measure of the expectation satisfaction level based on the organizational expectations prior to implementation of ISO 27001 and the actual results obtained after certification. Thus, effectiveness focuses on how well objectives have been achieved rather than how well processes have been followed. The effectiveness of ISO 27001 is in preventing or minimizing the exposure to information security incidents in the real world. In a scenario where there has been so much investment in adopting the framework and subsequent certification resulting in high levels of stakeholder assurance, the focus is to identifying the areas where it is effective. But more importantly, it also focus on the areas where there are gaps, leading to information security risks and/or an incident even in a situation where the framework is adhered to and certification against it exists. Companies that have ISO 27001 certification and audits gain an improved risk based approach to information security management through an ongoing process of risk assessment and risk mitigation, which helps them to adequately prioritize the implementation of countermeasures, and strengthen their security posture through the ISO rigorous testing. Organizations are then able to demonstrate that they have well internal controls over financial processes, and, more importantly, they can help mitigate information security risks by operating under one system rather than two. This approach can complement the Plan, Do, Check, Act (PDCA) process, which is a widely accepted system to drive continual improvement. The analysis results support organizations and security managers at identifying systems they can use to achieve greater efficiency in the information security management process.

Why it matters

OpenAlex reports 10 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Effectiveness of ISO 27001 as an information security system is a measure of the expectation satisfaction level based on the organizational expectations prior to implementation of ISO 27001 and the actual results obtained after certification. Thus, effectiveness focuses on how well objectives have been achieved rather than how well processes have been followed. The effectiveness of ISO 27001 is in preventing or minimizing the exposure to information security incidents in the real world. In a scenario where there has been so much investment in adopting the framework and subsequent certification resulting in high levels of stakeholder assurance, the focus is to identifying the areas where it is effective. But more importantly, it also focus on the areas where there are gaps, leading to information security risks and/or an incident even in a situation where the framework is adhered to and certification against it exists. Companies that have ISO 27001 certification and audits gain an improved risk based approach to information security management through an ongoing process of risk assessment and risk mitigation, which helps them to adequately prioritize the implementation of countermeasures, and strengthen their security posture through the ISO rigorous testing. Organizations are then able to demonstrate that they have well internal controls over financial processes, and, more importantly, they can help mitigate information security risks by operating under one system rather than two. This approach can complement the Plan, Do, Check, Act (PDCA) process, which is a widely accepted system to drive continual improvement. The analysis results support organizations and security managers at identifying systems they can use to achieve greater efficiency in the information security management process.

Key concepts: Information security management system, ITIL security management, Information security management, Information security standards, Information security, Risk analysis (engineering), Certification, Business

Related papers

Back to paper searchBrowse research topicsOriginal source