September 6, 2010

A Business Case for ISO 27001 Certification

Tom Carlson and Robert Forbes

ISO 27001 is intended to provide guidance on how to manage information security for an organization. To expand on this, the ISO standard is focused on an organization as a whole, including all information types, systems, people, policies, processes, and technologies. This chapter sets out the benefits and provides a business case for an information security management system (ISMS) that conforms to the ISO 27001 standard.