Benefits of ISO 27001 for the Company
Some benefits of ISO 27001 implementation for the company such as:
1 Improvement of security: General improvement of information security effectiveness The standard covers both the technological aspects of security and the other aspects:
corporate security, physical security, etc. Independent review of your information security management system Enhanced information security awareness Mechanisms to measure the effectiveness of the management system
2.Good governance: Awareness and empowerment of personnel regarding information security Decrease of lawsuit risks against upper management in virtue of the ‘‘due care’’ and
the ‘‘due diligence’’ principles The opportunity to identify the weaknesses of the ISMS and to provide corrections Increase of the top management accountability for information security
3. Conformity: To other ISO standards
To OECD (Organization for Economic Co-operation and Development) principles To industry standards, example: PCI-DSS (Payment Card Industry Data Security
Standard), Basel II (for banking industry) To national and regional laws
4. Cost reduction: Decision makers often ask to justify the profitability of projects and demand concrete
and measurable return benefits. A new financial evaluation concept has emerged to
treat specifically the information security field: Return on Security Investment (ROSI).
ROSI is a concept derived from Return on Investment (ROI). It can be interpreted as
the security project’s financial profit taking into account its total cost over a given
period of time.
5. Marketing: Differentiation provides a competitive advantage for the organization Satisfaction of requirements of customer or other interested parties Consolidating confidence of customers, suppliers and partners of the organization