need help to Fix research paper about ISO27001 need to done in 6 hr.

profilepimrypie
Boonchoo_week6.docx

2

Addressing Information Security Risks by Adopting Standards

Manchoopaporn Boonchoo

University of the Cumberlands

Enterprise Risk Management

ITS 835- 40

Dr. Abiodun Adeleke (Abbey)

06/13/2021

Addressing Information Security Risks by Adopting Standards

ISO 27001 standard will work efficiently in the organization operating within the current technological environment where there are higher possibilities of a breach in the risk of loss of data that an institution employs in executing its function. Furthermore, it is to allow it to be competitive relative to other firms within its operating environment (Lopes et al., 2019). The International Organization for Standardization (ISO) offers structured information security standards that address best-practice options and recommendations for organizational information security management. It enables an organization to shield any sought of external interference of their data used to perform its technological activities and protect the users from the problems that arise.

Therefore, data protection policies are necessary for cybersecurity protection due to recurring interferences that firms experience with expanding the technical scope globally. An organization that offers the license for cyber practices enables institutions to have the ability to protect their patent rights of the activities they conduct using the technology they employ and hold liable any entity that compromises the safety standards of the organization (Cram et al., 2019). Thereby, organizations need to adopt effective policies, processes, and procedures to protect the users' data they control in the current technological era. To ensure that the people who submit their details while using an online platform are protected from any problem that may arise due to the interference of an organization's technological platform.

An information security management system (ISMS) framework issues policies and controls measures that are effective for managing security and risks associated with the systematic elements within organizational information and data security. The framework has various components that render it effective in ensuring the organizational data and technology architecture are protected from any interference that may compromise the organization's functioning and the users in the platform (Cram et al., 2019). ISMS's effectiveness comprises the rights that a user has to data portability, which allows them to use data from one electronic device to the other without having a limitation for any logins they made in another platform. Such provisions allow the user to have control of their information. At the same time, the organization limits its monopoly of using the personal data that belongs to the people in a restrictive way which might be exploitative. Thereby, such policies enable the technological advancement of an organization. It is based on the need of the people who use the platform in their activities and impose control measures to secure the firm's data.

An effective ISMS aids in the elimination of threats and vulnerabilities that may be experienced in a given cyber process that people are involved in doing. It helps reduce the rates of virus attacks that aim to induce programs in a cyber system that compromise the activities of an organization and the users involved in the activities tailored by the firm. The threats comprise altering the users' data and enabling them to be used with entities that should not be associated with the information. Therefore, a practical ISMS framework ensures that the flow of information within an organization is well monitored and the circulation of data is maintained securely (Cram et al., 2019). That will ensure that the people using the platform have their information handles with absolute security. So, it is when there is increased technological knowledge, and some people are using it in an unethical manner to jeopardize the conditions in which the data are considered beneficial.

Effective ISMS will provide an organization with the opportunity to provide security to the shareholders, the clients, and the partners. The people's data are secured in the organization's database in an ISO-certified manner, which offers the individuals security in case some sabotage has been experienced. As a result, the organization experience more security awareness and enables it to have a more organized way to ensure that there is no leakage of information to the people without the firm that may wish to cause disruptions in how the information is used for their gains (Patón-Romero et al., 2019). Therefore, ISMS increases the capacity of data that belongs to an institution and users who are using a given platform to manage and survive any compromise that may be experienced while operating the platforms. Thereby, effective ISMS will ensure that an organization has a framework to identify a problem and protect its information from being handled by unauthorized people who may compromise the data.

COBIT framework help in the creation of alignment between the business and the information technology employed to enhance the operations of an organization. It provided the IT governance framework necessary to govern an organization on how they will employ their resources to safeguard the information they possess within the firm. It will ensure that the organization can have a structure that will inform them on the organization's management, how the data they possess is used, and any information leakage to unauthorized people and elements (Al-Ahmad & Mohammad, 2013). In addition, the framework ensures that an organization can comply with the guidelines that protect the use of data within organizations and mandate them to have an established way to ensure that the users of their platforms are aware of how their data are handled within the institution.

The organization employs the COBIT framework for audit purposes to ensure that a firm can account for how the information in its possession is managed in a regulated manner. It helps an organization to conduct a risk assessment of the problems that the institution has experienced. It informs their subsequent security measures that will allow a company to counter any risk that the organization may face in the future time. Therefore, the framework will allow an organization to create IT policies and procedures that will be followed to ensure that the institution's information is protected from unauthorized people (Al-Ahmad & Mohammad, 2013). It will enable an organization to be able to trace the leakages that exist, which can be used through cyberattacks to render an organization vulnerable in the means by which it is handling the data it possesses. Therefore, COBIT is used to standardize the cyber activities undertaken by an organization, ensuring that the firm can use their technology effectively in meeting their demands without having their data compromised within the systems they have employed to execute their functions.

Better framework use will ensure that the data at the disposal of an organization are used effectively. The ISO standards ensure all the organizations that employ the use of technology have similar procedures that ensure the data that belong to the users are protected and allow fairness in using the resources. The standards set within the ISO framework ensure that an organization can make sure that it can protect the data that people have trusted them with and counter any cyberattack that may be experienced to compromise the information (Lopes et al., 2019). Information technology frameworks are effectively used when they are employed to counter problems that are designed for them. It will allow an organization to have the ability to understand the procedures and the demands of the system they have employed to protect the institution from disruptions. Therefore, the ISO standards and the framework which govern various organizations must ensure that an organization meets the required standards.

References

Al-Ahmad, W., & Mohammad, B. (2013). Addressing information security risks by adopting standards. International Journal of Information Security Science, 2(2), 28-43.

https://ijiss.org/~ijissorg/ijiss/index.php/ijiss/article/viewFile/20/pdf_5

Cram, W. A., Proudfoot, J. G., & D’arcy, J. (2017). Organizational information security policies: a review and research framework. European Journal of Information Systems, 26(6), 605-641.

https://link.springer.com/article/10.1057/s41303-017-0059-9

Lopes, M., Guarda, T. & Oliveira, P. (2019). How ISO 27001 Can help achieve GDPR compliance. 2019 14th Iberian Conference on Information Systems and Technologies (CISTI), pp. 1-6.

https://ieeexplore.ieee.org/document/8760937?arnumber=8760937

Patón-Romero, J. D., Baldassarre, M. T., Rodriguez, M., & Piattini, M. (2019). Application of ISO 14000 to information technology governance and management. Computer Standards & Interfaces, 65, 180-202.

https://www.sciencedirect.com/science/article/abs/pii/S0920548918303684