Skip to main content
34
Views
136
Downloads
Reviewed article

The Role of Standards in Enhancing Cybersecurity and Business Continuity Management for Organizations

How to cite:
Ilkka Tikanmäki, Jari Savolainen, Harri Ruoslahti
"The Role of Standards in Enhancing Cybersecurity and Business Continuity Management for Organizations"
Information & Security: An International Journal,
55
no. 1
(2024):
63-78 .
https://doi.org/10.11610/isij.5523

The Role of Standards in Enhancing Cybersecurity and Business Continuity Management for Organizations

Source:

Information & Security: An International Journal,
Volume: 55,
Issue1,
p.63-78
(2024)

Abstract:

Standards are documented specifications that ensure that products, services, and systems are secure, reliable, and consistent. They unify and improve industries with requirements, recommendations, or procedures for activities or products. Standards provide information on security management systems based on industry best practices. The DYNAMO project promotes an integrated approach designed to enhance cyber situational awareness for critical sectors such as healthcare, energy, and maritime transport. This study is part of project efforts to map relevant cybersecurity standards with the research question: how can standards enhance cyber resilience? 

The article presents a desktop study, including a cross-case analysis. Results show that surprisingly little is written on the practical experiences of using standards, with a lack of evidence-based experience in implementing and using standards in practice. Many benefits are presented by the standardization bodies themselves. These include compliance with legal requirements, competitive advantages, lower costs, and organisational improvements for ISO 22301. Information security professionals can use ISO/IEC 27001 to help define requirements and enhance a company’s compliance and organisational improvement, and the NIST framework supports them in making informed risk management decisions while offering a high-level strategic view of an organisation’s cybersecurity risk management lifecycle. 

34
Views
136
Downloads