need help to Fix research paper about ISO27001 need to done in 6 hr.
2
Addressing Information Security Risks by Adopting Standards
Manchoopaporn Boonchoo
University of the Cumberlands
Enterprise Risk Management
ITS 835- 40
Dr. Abiodun Adeleke (Abbey)
06/13/2021
Addressing Information Security Risks by Adopting Standards
ISO 27001 standard will work efficiently in the organization operating within the current technological environment where there are higher possibilities of a breach in the risk of loss of data that an institution employs in executing its function. Furthermore, it is to allow it to be competitive relative to other firms within its operating environment (Lopes et al., 2019). The International Organization for Standardization (ISO) offers structured information security standards that address best-practice options and recommendations for organizational information security management. It enables an organization to shield any sought of external interference of their data used to perform its technological activities and protect the users from the problems that arise.
Therefore, data protection policies are necessary for cybersecurity protection due to recurring interferences that firms experience with expanding the technical scope globally. An organization that offers the license for cyber practices enables institutions to have the ability to protect their patent rights of the activities they conduct using the technology they employ and hold liable any entity that compromises the safety standards of the organization (Cram et al., 2019). Thereby, organizations need to adopt effective policies, processes, and procedures to protect the users' data they control in the current technological era. To ensure that the people who submit their details while using an online platform are protected from any problem that may arise due to the interference of an organization's technological platform.
An information security management system (ISMS) framework issues policies and controls measures that are effective for managing security and risks associated with the systematic elements within organizational information and data security. The framework has various components that render it effective in ensuring the organizational data and technology architecture are protected from any interference that may compromise the organization's functioning and the users in the platform (Cram et al., 2019). ISMS's effectiveness comprises the rights that a user has to data portability, which allows them to use data from one electronic device to the other without having a limitation for any logins they made in another platform. Such provisions allow the user to have control of their information. At the same time, the organization limits its monopoly of using the personal data that belongs to the people in a restrictive way which might be exploitative. Thereby, such policies enable the technological advancement of an organization. It is based on the need of the people who use the platform in their activities and impose control measures to secure the firm's data.
An effective ISMS aids in the elimination of threats and vulnerabilities that may be experienced in a given cyber process that people are involved in doing. It helps reduce the rates of virus attacks that aim to induce programs in a cyber system that compromise the activities of an organization and the users involved in the activities tailored by the firm. The threats comprise altering the users' data and enabling them to be used with entities that should not be associated with the information. Therefore, a practical ISMS framework ensures that the flow of information within an organization is well monitored and the circulation of data is maintained securely (Cram et al., 2019). That will ensure that the people using the platform have their information handles with absolute security. So, it is when there is increased technological knowledge, and some people are using it in an unethical manner to jeopardize the conditions in which the data are considered beneficial.
Effective ISMS will provide an organization with the opportunity to provide security to the shareholders, the clients, and the partners. The people's data are secured in the organization's database in an ISO-certified manner, which offers the individuals security in case some sabotage has been experienced. As a result, the organization experience more security awareness and enables it to have a more organized way to ensure that there is no leakage of information to the people without the firm that may wish to cause disruptions in how the information is used for their gains (Patón-Romero et al., 2019). Therefore, ISMS increases the capacity of data that belongs to an institution and users who are using a given platform to manage and survive any compromise that may be experienced while operating the platforms. Thereby, effective ISMS will ensure that an organization has a framework to identify a problem and protect its information from being handled by unauthorized people who may compromise the data.
The organization employs the COBIT framework for audit purposes to ensure that a firm can account for how the information in its possession is managed in a regulated manner. It helps an organization to conduct a risk assessment of the problems that the institution has experienced. It informs their subsequent security measures that will allow a company to counter any risk that the organization may face in the future time. Therefore, the framework will allow an organization to create IT policies and procedures that will be followed to ensure that the institution's information is protected from unauthorized people (Al-Ahmad & Mohammad, 2013). It will enable an organization to be able to trace the leakages that exist, which can be used through cyberattacks to render an organization vulnerable in the means by which it is handling the data it possesses. Therefore, COBIT is used to standardize the cyber activities undertaken by an organization, ensuring that the firm can use their technology effectively in meeting their demands without having their data compromised within the systems they have employed to execute their functions.
Better framework use will ensure that the data at the disposal of an organization are used effectively. The ISO standards ensure all the organizations that employ the use of technology have similar procedures that ensure the data that belong to the users are protected and allow fairness in using the resources. The standards set within the ISO framework ensure that an organization can make sure that it can protect the data that people have trusted them with and counter any cyberattack that may be experienced to compromise the information (Lopes et al., 2019). Information technology frameworks are effectively used when they are employed to counter problems that are designed for them. It will allow an organization to have the ability to understand the procedures and the demands of the system they have employed to protect the institution from disruptions. Therefore, the ISO standards and the framework which govern various organizations must ensure that an organization meets the required standards.
References
Al-Ahmad, W., & Mohammad, B. (2013). Addressing information security risks by adopting standards. International Journal of Information Security Science, 2(2), 28-43.
https://ijiss.org/~ijissorg/ijiss/index.php/ijiss/article/viewFile/20/pdf_5
Cram, W. A., Proudfoot, J. G., & D’arcy, J. (2017). Organizational information security policies: a review and research framework. European Journal of Information Systems, 26(6), 605-641.
https://link.springer.com/article/10.1057/s41303-017-0059-9
https://ieeexplore.ieee.org/document/8760937?arnumber=8760937
Patón-Romero, J. D., Baldassarre, M. T., Rodriguez, M., & Piattini, M. (2019). Application of ISO 14000 to information technology governance and management. Computer Standards & Interfaces, 65, 180-202.
https://www.sciencedirect.com/science/article/abs/pii/S0920548918303684