Influence of established information security governance and infrastructure on future security certifications

Ivan Sedinic, Zrinka Lovrić · International Convention on Information and Communication Technology, Electronics and Microelectronics · 2013

In today business environment different security certificates are not any more “nice to have” feature but business prerequisite for service providers. PCI DSS certification is a must for card issuers and merchants and ISO27001 certification is very often prerequisite to qualify for ICT services offering. In this paper will be shown how proper security governance and security framework on which is built adequate security infrastructure could simplify and speed up certification process, while at the same time reduce cost of certification. Additionally, on examples of ISO27001 and PCI DSS, influence of one existing certificate on certification process for other certificate will be analyzed.

Read the paper · More papers on PaperTik