Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
The effects of ISO 27001 certification: An interview study investigating what changes have small to medium-sized organizations in Sweden experienced after an ISO 27001 certification
University of Skövde, School of Informatics.
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

With the increasing digitalization of society, where threats of data breaches and information leaks are growing exponentially, the importance of a structured and effective management of information security has become increasingly apparent. This realization has contributed to organizations prioritizing efforts to ensure the secure management of information, making information security management systems (ISMS) a prominent component among organizations. With the increased demand for this, ISO 27001 certification has emerged as a key strategy for organizations to increase information security. Given the lack of research on this certificate, especially inthe Swedish context, this study aims to investigate what effects small to medium-sized organizations experience after an ISO 27001 certification. Using a qualitative research method, eleven semi-structured interviews were conducted where the results were discussed and compared with previous research in the field. The results indicate that organization experiences a lot of improvements after the ISO 27001 certification, which are both internal and external improvements. The findings show that organizations experience efficiency improvements, improved security and risk management, business benefits, and better customer relations. In addition, the findings also indicate that the certificate is fulfilling its purpose and that organizations are satisfied with the end result and choose to recertify.

Place, publisher, year, edition, pages
2024. , p. 40, ii
Keywords [en]
Information security, ISMS, ISO 27001, certification
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-23961OAI: oai:DiVA.org:his-23961DiVA, id: diva2:1871578
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2024-06-17 Created: 2024-06-17 Last updated: 2024-06-17Bibliographically approved

Open Access in DiVA

fulltext(367 kB)215 downloads
File information
File name FULLTEXT01.pdfFile size 367 kBChecksum SHA-512
4a5fbc19a6be7016f87115788f9a7651ffb2b9cfa3a0a845bdd83186608cf1f6bed94d969b0f3f2873db76d38b716b10a1976374b68558a9a6b46c5412102aa3
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 215 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 829 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf