Four Key Benefits of ISO 27001 Implementation

Have you ever tried to convince your management todifferentiate you in the eyes of your customers. ISO
fund the implementation of information security? If you27001 could be indeed a unique selling point, especially if
have, you probably know how it feels - they will askyou handle clients' sensitive information.
you how much it costs, and if it sounds too expensive3. Lowering the expenses
they will say no.Information security is usually considered as a cost
Actually, you shouldn't blame them - after all, theirwith no obvious financial gain. However, there is
ultimate responsibility is profitability of the company.financial gain if you lower your expenses caused by
That means, their every decision is based on theincidents. You probably do have interruption in service,
balance between investment and benefit, or to put it inor occasional data leakage, or disgruntled employees.
management's language - ROI (return on investment).Or disgruntled former employees.
This means you have to do your homework firstThe truth is, there is still no methodology and/or
before trying to propose such an investment - thinktechnology to calculate how much money you could
carefully how to present the benefits, using languagesave if you prevented such incidents. But it always
the management will understand and will endorse.sounds good if you bring such cases to management's
I'll try to help you - the benefits of information security,attention.
especially the implementation of ISO 27001 are4. Putting your business in order
numerous. But in my experience, the following four areThis one is probably the most underrated - if you are a
the most important:company which has been growing sharply for the last
1. Compliancefew years, you might experience problems like - who
It might seem odd to list this as the first benefit, but ithas to decide what, who is responsible for certain
often shows the quickest "return on investment" - if aninformation assets, who has to authorize access to
organization must comply to various regulationsinformation systems etc.
regarding data protection, privacy and IT governanceISO 27001 is particularly good in sorting these things out
(particularly if it is a financial, health or government- it will force you to define very precisely both the
organization), then ISO 27001 can bring in theresponsibilities and duties, and therefore strengthen
methodology which enables to do it in the mostyour internal organization.
efficient way.To conclude - ISO 27001 could bring in many benefits
2. Marketing edgebesides being just another certificate on your wall. In
In a market which is more and more competitive, it ismost cases, if you present those benefits in a clear
sometimes very difficult to find something that willway, the management will start listening to you.