ISO27001 as a Tool for Availability Management

Jan Marius Evang · 2022

Many companies seek to gain reputation by going through a certification process, and the standard of choice for many companies will be the ISO 27001:2013 standard [1], A thorough literature review on ISO27001 research [8] found that only 26% of the studies have cited outcomes of the ISO27001 certification, and only 3 papers focus explicitly on the impact of the standard. Neither of these focus on availability and risk, and no research provides real data from a risk registry showing the standard’s effect. In this research we analyse the controls of the standard from the point of view of a Network Operations Centre. We further analyse a global network operator’s risk registry over a 5-year period and show how the risks and risk improvements relate to the ISO27001 information security objectives. The results show that the implementation of ISO27001 caused a significant reduction of risk in all areas, and argues that the ISO27001 standard is well suited to reducing the operator’s risk related to the objects of confidentiality, integrity and availability.

Read the paper · More papers on PaperTik