The required article readings this week give a good discussion and look at some of the frameworks that are used to manage risk within organizations and enterprises. One of the readings this week provided an introduction and comparison of different frameworks. As with anything, there are going to be strengths and weaknesses to all approaches.
For your week 6 research paper, please address the following in a properly formatted research paper:
- Do you think that ISO 27001 standard would work well in the organization that you currently or previously have worked for? If you are currently using ISO 27001 as an ISMS framework, analyze its effectiveness as you perceive in the organization.
- Are there other frameworks mentioned has been discussed in the article that might be more effective?
- Has any other research you uncover suggest there are better frameworks to use for addressing risks?
Your paper should meet the following requirements:
- Be approximately four to six pages in length, not including the required cover page and reference page.
- Follow APA 7 guidelines. Your paper should include an introduction, a body with fully developed content, and a conclusion.
- Support your answers with the readings from the course and at least two scholarly journal articles to support your positions, claims, and observations, in addition to your textbook. The UC Library is a great place to find resources.
- Be clearly and well-written, concise, and logical, using excellent grammar and style techniques. You are being graded in part on the quality of your writing
Al-Ahmad, W., & Mohammad, B. (2013). Addressing Information Security Risks by Adopting Standards. International Journal of Information Security Science, 2(2), 28–43. http://search.ebscohost.com/
Answer preview
One benefit that the organization has benefitted by adopting the standard is the protection of confidential data. Organizations that intend to adopt the standard have to comply with the security protocols set in the standard. The standard requires organizations to set up rules to protect sensitive data and intellectual property of organizations. My current organization is a telecommunication company, and in the past, customers were complaining that they were getting calls from strange numbers. After conducting a security audit, it was found that the issue was a software flaw that allowed attackers to access customer data. After implementing the ISO 27001 standard’s security protocols, customer data was secure, and there were few issues that customers reported on being scammers. The increased safety of sensitive organizational data improves the image of the organization. Customer trust increased, and overall, the reputation of the company also improved.
[1991 Words]