01955nas a2200169 4500000000100000008004100001653001800042653003500060653001400095100002100109700002000130700002000150245010600170300001100276490000700287520149100294 2024 d10aCybersecurity10aBusiness Continuity Management10astandards1 aIlkka Tikanmäki1 aJari Savolainen1 aHarri Ruoslahti00aThe Role of Standards in Enhancing Cybersecurity and Business Continuity Management for Organizations a63-78 0 v553 a
Standards are documented specifications that ensure that products, services, and systems are secure, reliable, and consistent. They unify and improve industries with requirements, recommendations, or procedures for activities or products. Standards provide information on security management systems based on industry best practices. The DYNAMO project promotes an integrated approach designed to enhance cyber situational awareness for critical sectors such as healthcare, energy, and maritime transport. This study is part of project efforts to map relevant cybersecurity standards with the research question: how can standards enhance cyber resilience?
The article presents a desktop study, including a cross-case analysis. Results show that surprisingly little is written on the practical experiences of using standards, with a lack of evidence-based experience in implementing and using standards in practice. Many benefits are presented by the standardization bodies themselves. These include compliance with legal requirements, competitive advantages, lower costs, and organisational improvements for ISO 22301. Information security professionals can use ISO/IEC 27001 to help define requirements and enhance a company’s compliance and organisational improvement, and the NIST framework supports them in making informed risk management decisions while offering a high-level strategic view of an organisation’s cybersecurity risk management lifecycle.