Enhancing Information Security Management in Small and Medium Enterprises (SMEs) Through ISO 27001 Compliance

Fabricio Mera-Amores, Henry N. Roa*

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The ISO 27001 standard is a crucial framework for establishing Information Security Management Systems (ISMS) in organizations, irrespective of their size or sector. Its core objective is safeguarding information confidentiality, integrity, and availability through security controls and regular audits. ISO 27001 certification assures stakeholders of effective security control implementation and sensitive data management. Implementing ISO 27001 is ideal for ensuring information security but can be cost-prohibitive due to the need for process improvements, role adaptations, and a lengthy implementation process. Smaller organizations, such as SMEs, often struggle to afford the associated expenses. Consequently, many organizations opt for practical yet incomplete information security solutions. However, adopting ISO 27001 can be a valuable tool for managing information security without incurring substantial costs. This research explores how organizations can utilize ISO 27001 as a strategic tool to enhance information security management without immediate full-scale implementation. This approach provides a stepping stone towards eventual ISO 27001 certification, allowing organizations to gradually improve their information security capabilities while managing costs effectively.

Original languageEnglish
Title of host publicationAdvances in Information and Communication - Proceedings of the 2024 Future of Information and Communication Conference FICC
EditorsKohei Arai
PublisherSpringer Science and Business Media Deutschland GmbH
Pages197-207
Number of pages11
ISBN (Print)9783031539626
DOIs
StatePublished - 2024
EventFuture of Information and Communication Conference, FICC 2024 - Berlin, Germany
Duration: 4 Apr 20245 Apr 2024

Publication series

NameLecture Notes in Networks and Systems
Volume920 LNNS
ISSN (Print)2367-3370
ISSN (Electronic)2367-3389

Conference

ConferenceFuture of Information and Communication Conference, FICC 2024
Country/TerritoryGermany
CityBerlin
Period4/04/245/04/24

Bibliographical note

Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2024.

Keywords

  • ISO 27001
  • Information security
  • SMEs

Cite this