An Effect Analysis of ISO/IEC 27001 Certification on Technical Security of Norwegian Grid Operators

Oyvind Anders Arntzen Toftegaard · 2022 IEEE International Conference on Big Data (Big Data) · 2022

Digital vulnerabilities and the risk of cyberattacks against the electric grid are a concern for both governments and businesses. There are several opportunities for authorities to impose security measures on grid operators to reduce risks. German legislation requires grid operators to certify their information security management system according to the ISO/IEC 27001 standard. Some researchers have tried to measure various effects of ISO/IEC 27001 certification, but nobody has so far assessed the effect of certification on technical security performance. This study hypothesizes that ISO/IEC 27001 certification will lead to increased technical security performance for Norwegian grid operators. A Quasi-Experimental methodology based on Difference in Differences logic is applied to test the hypothesis. 11.010 technical security scores from 400 entities were collected through BlackKite’s Technical Cyber Rating tool and Security Scorecard’s Security Rating tool. The effect of ISO/IEC 27001 certification was estimated by taking the difference in technical security performance between uncertified Norwegian grid operators and certified German grid operators, and subtracting the difference between a control group of Norwegian and German banks. The analysis predicts a significant positive effect for small Norwegian grid operators, it is inconclusive for medium-sized grid operators, and it indicates a negative effect for large grid operators. Since the research was limited to externally identifiable security mechanisms only, more research is necessary to fully understand the effect of ISO/IEC 27001 certification on technical security performance.

Read the paper · More papers on PaperTik