Is ISO 27001 worth it?
Cath Everett · Computer Fraud & Security · 2011
The ISO 27001 information security management system standard is well respected and internationally recognised. But although it has been around in various guises for more than a decade, accreditation levels remains low because of its reputation for taking a lot of time, effort and money. Cath Everett explores which sectors have been the most forthcoming in compliance terms, what the key drivers are and how market forces are starting to bring about change. She also provides some key best practice advice about how to achieve conformance in the least painful way possible. Even though the internationally recognised ISO 27001 information security management system standard has been around in various guises for the past decade, uptake is not as widespread as might be expected.