EFFECTIVENESS OF ISO 27001, AS AN INFORMATION SECURITY MANAGEMENT SYSTEM: AN ANALYTICAL STUDY OF FINANCIAL ASPECTS
Dr N K Sharma () and
Prabir Kumar Dash ()
Additional contact information
Dr N K Sharma: Faculty, Department of EAFM University of Rajasthan, Jaipur, India
Prabir Kumar Dash: Faculty, Department of EAFM University of Rajasthan, Jaipur, India
Far East Journal of Psychology and Business, 2012, vol. 9 No 3 Paper 5 December, issue 5, 57-71
Abstract:
Effectiveness of ISO 27001 as an information security system is a measure of the expectation satisfaction level based on the organizational expectations prior to implementation of ISO 27001 and the actual results obtained after certification. Thus, effectiveness focuses on how well objectives have been achieved rather than how well processes have been followed. The effectiveness of ISO 27001 is in preventing or minimizing the exposure to information security incidents in the real world. In a scenario where there has been so much investment in adopting the framework and subsequent certification resulting in high levels of stakeholder assurance, the focus is to identifying the areas where it is effective. But more importantly, it also focus on the areas where there are gaps, leading to information security risks and/or an incident even in a situation where the framework is adhered to and certification against it exists. Companies that have ISO 27001 certification and audits gain an improved risk based approach to information security management through an ongoing process of risk assessment and risk mitigation, which helps them to adequately prioritize the implementation of countermeasures, and strengthen their security posture through the ISO rigorous testing. Organizations are then able to demonstrate that they have well internal controls over financial processes, and, more importantly, they can help mitigate information security risks by operating under one system rather than two. This approach can complement the Plan, Do, Check, Act (PDCA) process, which is a widely accepted system to drive continual improvement. The analysis results support organizations and security managers at identifying systems they can use to achieve greater efficiency in the information security management process.
Keywords: Information Security; Information Security Management; Information Security Management System (ISMS); ISO 27001 Standards. (search for similar items in EconPapers)
JEL-codes: M1 (search for similar items in EconPapers)
Date: 2012
References: View complete reference list from CitEc
Citations: View citations in EconPapers (1)
Downloads: (external link)
http://www.fareastjournals.com/files/FEJPBV9N3P5.pdf (application/pdf)
http://www.fareastjournals.com/archive_detail.aspx?jid=18&aid=31 (text/html)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:fej:articl:v:9c:y:2012:i:5:p:57-71
Access Statistics for this article
More articles in Far East Journal of Psychology and Business from Far East Research Centre
Bibliographic data for series maintained by Jim Chau ( this e-mail address is bad, please contact ).