IDEAS home Printed from https://ideas.repec.org/a/fej/articl/v9cy2012i5p57-71.html
   My bibliography  Save this article

Effectiveness Of Iso 27001, As An Information Security Management System: An Analytical Study Of Financial Aspects

Author

Listed:
  • Dr N K Sharma

    (Faculty, Department of EAFM University of Rajasthan, Jaipur, India)

  • Prabir Kumar Dash

    (Faculty, Department of EAFM University of Rajasthan, Jaipur, India)

Abstract

Effectiveness of ISO 27001 as an information security system is a measure of the expectation satisfaction level based on the organizational expectations prior to implementation of ISO 27001 and the actual results obtained after certification. Thus, effectiveness focuses on how well objectives have been achieved rather than how well processes have been followed. The effectiveness of ISO 27001 is in preventing or minimizing the exposure to information security incidents in the real world. In a scenario where there has been so much investment in adopting the framework and subsequent certification resulting in high levels of stakeholder assurance, the focus is to identifying the areas where it is effective. But more importantly, it also focus on the areas where there are gaps, leading to information security risks and/or an incident even in a situation where the framework is adhered to and certification against it exists. Companies that have ISO 27001 certification and audits gain an improved risk based approach to information security management through an ongoing process of risk assessment and risk mitigation, which helps them to adequately prioritize the implementation of countermeasures, and strengthen their security posture through the ISO rigorous testing. Organizations are then able to demonstrate that they have well internal controls over financial processes, and, more importantly, they can help mitigate information security risks by operating under one system rather than two. This approach can complement the Plan, Do, Check, Act (PDCA) process, which is a widely accepted system to drive continual improvement. The analysis results support organizations and security managers at identifying systems they can use to achieve greater efficiency in the information security management process.

Suggested Citation

  • Dr N K Sharma & Prabir Kumar Dash, 2012. "Effectiveness Of Iso 27001, As An Information Security Management System: An Analytical Study Of Financial Aspects," Far East Journal of Psychology and Business, Far East Research Centre, vol. 9(5), pages 57-71, December.
  • Handle: RePEc:fej:articl:v:9c:y:2012:i:5:p:57-71
    as

    Download full text from publisher

    File URL: http://www.fareastjournals.com/files/FEJPBV9N3P5.pdf
    Download Restriction: no

    File URL: http://www.fareastjournals.com/archive_detail.aspx?jid=18&aid=31
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    Information Security; Information Security Management; Information Security Management System (ISMS); ISO 27001 Standards.;
    All these keywords.

    JEL classification:

    • M1 - Business Administration and Business Economics; Marketing; Accounting; Personnel Economics - - Business Administration

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:fej:articl:v:9c:y:2012:i:5:p:57-71. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Jim Chau (email available below). General contact details of provider: http://www.fareastjournals.com/journal_detail.aspx?jid=18 .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.