Expert Advice Community

Guest

Cost avoidance due to ISO ISMS

  Quote
Guest
Guest user Created:   Sep 17, 2017 Last commented:   Sep 17, 2017

Cost avoidance due to ISO ISMS

CEO's I have visited are worried that ISO Certification costs are higher than ever. Is there information that shows the cost avoidance - ISO certification can bring to the organization?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 17, 2017

Answer: Yes, there is. For ISO 27001 one good reference is the Cost of Cyber Crime Report from Ponemon Institute (https://www.ponemon.org/library/2016-cost-of-cyber-crime-study-the-risk-of-business-innovation) (specifically see page 18 - Total cost of cyber crime for low versus high security profiles), but you have to be very careful when presenting these type of data to customers, because each organization has its unique context that can affect the risks to each one that are exposed and the impacts they may suffer, so basing on an opportunity to avoid costs in data from another organization can lead to wrong conclusions. You could say that these are only examples and that specif data about the client's organization must be evaluated to provide a more precise situation.

These articles will provide you further explanation regarding ISO 27001 costs:
- How much does ISO 27001 implementation cost? https://advisera.com/27001academy/blog/2011/02/08/how-much-does-iso-27001-implementation-cost/
- 5 ways to avoid overhead with ISO 27001 (and keep the costs down) https://advisera.com/27001academy/blog/2012/06/19/5-ways-to-avoid-overhead-with-iso-27001-and-keep-the-costs-down/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 17, 2017

Sep 17, 2017

Suggested Topics