ISO27001 as a Tool for Availability Management
Jan Marius Evang · 2022
Many companies seek to gain reputation by going through a certification process, and the standard of choice for many companies will be the ISO 27001:2013 standard [1], A thorough literature review on ISO27001 research [8] found that only 26% of the studies have cited outcomes of the ISO27001 certification, and only 3 papers focus explicitly on the impact of the standard. Neither of these focus on availability and risk, and no research provides real data from a risk registry showing the standard’s effect. In this research we analyse the controls of the standard from the point of view of a Network Operations Centre. We further analyse a global network operator’s risk registry over a 5-year period and show how the risks and risk improvements relate to the ISO27001 information security objectives. The results show that the implementation of ISO27001 caused a significant reduction of risk in all areas, and argues that the ISO27001 standard is well suited to reducing the operator’s risk related to the objects of confidentiality, integrity and availability.