Response to Discussion 5 ERM

profilePrashanthi
VenkataMadhuManaswiniVinnakota-Week5.docx

Venkata Madhu Manaswini Vinnakota

Week 5 Discussion board

ISO 27001:2013 (the current version of ISO 27001) is one of the most popular information security standards in the world. More companies are achieving ISO 27001 certification to underline the robustness of their information security management.

Compliance with ISO 27001 was previously about having a competitive edge, but as ISO 27001 certification becomes the norm for best-practice information security, it’s increasingly a minimum entry to a tender or contract renewal. Conformity to the standard can make the difference between winning and losing those all crucial tenders.

The ISO first released its family of standards in 2005 and since then has made periodic updates to the various policies. For ISO 27001, the latest significant changes were introduced in 2013 (Tamimi, 2019). Ownership of ISO 27001 is actually shared between the ISO and the International Electrotechnical Commission (IEC), which is a Swiss organization body that focuses primarily on electronic systems.

Ways in which ISO 27001 certification can benefit the organization:

Avoid hefty fines- ISO 27001 is the accepted global benchmark for the effective management of information assets. It enables organizations to avoid the costly penalties associated with non-compliance with data protection requirements and the financial losses resulting from data breaches.

Protect the reputation. Cyber-attacks are on the increase in Ireland, and can have a massive impact on your organisation and its importance (Hsu, Wang & Lu, 2016). An ISO 27001-certified ISMS (information security management system) helps protect your organisation and keeps you out of the headlines

Comply with business, legal, contractual and regulatory requirements. ISO 27001certification is also in line with rigid regulatory requirements such as the GDPR (General Data Protection Regulation), the NIS Directive (Directive on security of network and information systems), and other cybersecurity laws.

Improve structure and focus. When an organisation grows rapidly, it does not take long before there is confusion around responsibility for information assets. ISO 27001 helps organisations set up clear information risk responsibilities.

Reduce the need for frequent audits. ISO 27001 certification is globally accepted and demonstrates adequate security, reducing the need for repeat customer audits.

References

Tamimi, Moutasm & Aljohani, Reham & Alharbi, Boudor & Alshahrani, Manal. (2019). SECURITY REVIEW BASED ON ISO 27000/ ISO 27001/ ISO 27002 STANDARDS: A CASE STUDY RESEARCH.

Hsu, Carol & Wang, Tawei & Lu, Ang. (2016). The Impact of ISO 27001 Certification on Firm Performance. 4842-4848. 10.1109/HICSS.2016.600.