Filtern
Dokumenttyp
- Vortrag (13)
- Zeitschriftenartikel (7)
- Beitrag zu einem Tagungsband (5)
- Forschungsbericht (3)
- Sonstiges (2)
- Buchkapitel (1)
Sprache
- Englisch (18)
- Deutsch (12)
- Italienisch (1)
Schlagworte
- ISO/IEC 27001 (11)
- Zertifizierung (10)
- Konformitätsbewertung (9)
- Information security (7)
- QI-FoKuS (7)
- COVID-19 (6)
- Certification (6)
- Corona (6)
- Managementsysteme (5)
- Web Mining (5)
Organisationseinheit der BAM
Eingeladener Vortrag (wissenschaftliche Konferenzen)
- nein (13)
In the wake of digitalization, organizations are increasingly exposed to risks associated with security breaches and must take measures to preserve the confidentiality, integrity, and availability of information, and to ensure business continuity. The international standard ISO/IEC 27001 assists organizations in setting up, maintaining and continuously improving their information security management systems. However, despite high growth rates, its international diffusion rates are quite heterogeneous. This paper explores why the diffusion of the international management system standard ISO/IEC 27001 differs across countries. We classify the adoption of ISO/IEC 27001 as a ‘preventive organizational innovation’ and draw from diffusion studies of other management system standards and information security research to develop a set of hypotheses. These relate to the impact of cultural dimensions and national ICT development. We use a negative binomial regression model with panel data covering 57 countries over a 12-year period from 2006 to 2017 to test our hypotheses. We find that the cultural dimensions future orientation, power distance, and institutional collectivism as well as high ICT development are driving factors for the diffusion of ISO/IEC 27001. We derive policy recommendations and avenues for future research.
In the wake of digitalization, organizations are increasingly exposed to risks associated with security breaches and must take measures to preserve the confidentiality, integrity, and availability of information, and to ensure business continuity. The international standard ISO/IEC 27001 assists organizations in setting up, maintaining and continuously improving their information security management systems. However, despite high growth rates, its international diffusion rates are quite heterogeneous. This paper explores why the diffusion of the international management system standard ISO/IEC 27001 differs across countries. We classify the adoption of ISO/IEC 27001 as a ‘preventive organizational innovation’ and draw from diffusion studies of other management system standards and information security research to develop a set of hypotheses. These relate to the impact of cultural dimensions and national ICT development. We use a negative binomial regression model with panel data covering 57 countries over a 12-year period from 2006 to 2017 to test our hypotheses. We find that the cultural dimensions future orientation, power distance, and institutional collectivism as well as high ICT development are driving factors for the diffusion of ISO/IEC 27001. We derive policy recommendations and avenues for future research.
In the light of digitalization and recent EU policy initiatives, information is an important asset that organizations of all sizes and from all sectors should secure. However, in order to provide common requirements for the implementation of an information security management system, the internationally well-accepted ISO/IEC 27001 standard has not shown the expected growth rate since its publication more than a decade ago.In this article, we apply web mining to explore the adoption of ISO/IEC 27001 through a series of 2664 out of more than 900 000 German firms from the Mannheim Enterprise Panel dataset that refers to this standard on their websites. As a result, we present a “landscape” of ISO/IEC 27001 in Germany, which shows that firms not only seek certifications themselves but often refer on their websites to partners who are certified instead. Consequently, we estimate a probit model and find that larger and more innovative firms are more likely to be certified to ISO/IEC 27001 and that almost half of all certified firms belong to the information and communications technology (ICT) service sector. Based on our findings, we derive implications for policymakers and management and critically assess the suitability of web mining to explore the adoption of management system standards.
Ergebnisvorstellung im mitgliederexklusiven Webinar der Deutschen Gesellschaft für Qualität - DGQ zur Nutzung und Wirkung von genormten Managementsystemen als die erste Erhebung im Rahmen von QI-FoKuS. Neben der Motivation hinsichtlich der Anwendung verschiedener Normen, die Anforderungen an Managementsysteme darlegen, sowie den Wirkungen werden insbesondere die Zertifizierung für diese Normen sowie daran anknüpfend die Rolle und Funktion der Akkreditierung – und somit verschiedene Bausteine der QI – adressiert.
Lo scoppio della pandemia da Covid-19 ha travolto Italia a inizio anno e i suoi effetti sull’economia sono stati particolarmente pesanti.
Proprio per analizzare gli effetti della pandemia sul mercato della valutazione della conformità, lo scorso settembre Accredia, in collaborazione con l’Istituto Federale tedesco della Ricerca e del Collaudo dei Materiali (BAM), la Technische Universität di Berlino e l’Istituto Fraunhofer ISI, ha condotto un’indagine presso gli organismi e i laboratori accreditati in Italia.
Despite the increasing relevance of cybersecurity for companies’ performance, there is limited research on the adoption of ISO/IEC 27001, an international information security management standard. The aim of our study is to expand this limited body of literature. First, we analyse the influence of companies’ networks on the adoption of ISO/IEC 27001 as an organisational innovation based on firm website data and their hyperlinks, using the entire population of ISO/IEC 27001 certified firms identified via web mining. Second, we validate the method of constructing and analysing companies’ “digital layer” following the call for new methodological approaches to study the organisational adoption of innovations. Our findings reveal that companies' decision to adopt ISO/IEC 27001 increases significantly with their number of linkages to other companies and to those having the same certificate. Finally, their cognitive and organisational distances to linked partners have the expected inverted u-shaped influence on their own adoption decision.
Against the backdrop of numerous security breaches and cyber-attacks, organizations need to take measures to secure their data and information. However, the well-known management system standard ISO/IEC 27001 for information security has shown a lower adoption rate – in terms of annual ISO survey data – than was previously expected by scholars and practitioners. Through the lens of Rogers' diffusion of innovation theory, we consider the adoption of ISO/IEC 27001 as a 'preventive innovation' and aim to identify factors that help gain a better understanding of its adoption. Therefore, we conducted a survey among German organizations on the use and impact of management system standards, explicitly distinguishing between organizations that implement ISO/IEC 27001 and those that are additionally certified against this standard. This study provides insights and contributes to an advanced understanding of motives, impacts, barriers, and useful measures to increase adoption of ISO/IEC 27001. Our findings may be useful to organizations considering the adoption of this management system standard, to certification bodies providing certification services, and to policymakers seeking means to improve information security in organizations.
Digital transformation and especially the dramatic rise of products and services connected to the Internet of Things raise the questions on how to deal with the increasing risks related to Privacy and Cybersecurity. Presumably, these risks seem to be insufficiently reflected in the European Union’s current regulative system – by being neither part of the traditional definition of a safe product nor part of product-specific vertical or horizontal directives. Certification based on standards as underlying requirements has been identified by policymakers as an instrument to address this issue. The latest European draft regulation aims at increasing security and trust in ICT products and services, and reducing current European market fragmentation with a new Cybersecurity Certification Framework. Based on the results of a qualitative analysis of stakeholder statements on the current proposal on the Cybersecurity Act, this paper discusses elements of the proposed Cybersecurity Certification Framework. As a theoretical background, this paper provides definitions of the terms Safety, IT-security, and Cybersecurity, presents selected Cybersecurity-related standards and provides an outlook on future challenges to Conformity Assessment in the digital transformation.
Digital transformation and especially the dramatic rise of products and services connected to the Internet of Things raise the questions on how to deal with the increasing risks related to Privacy and Cybersecurity. Presumably, these risks seem to be insufficiently reflected in the European Union’s current regulative system – by being neither part of the traditional definition of a safe product nor part of product-specific vertical or horizontal directives. Certification based on standards as underlying requirements has been identified by policymakers as an instrument to address this issue. The latest European draft regulation aims at increasing security and trust in ICT products and services, and reducing current European market fragmentation with a new Cybersecurity Certification Framework. Based on the results of a qualitative analysis of stakeholder statements on the current proposal on the Cybersecurity Act, this paper discusses elements of the proposed Cybersecurity Certification Framework. As a theoretical background, this paper provides definitions of the terms Safety, IT-security, and Cybersecurity, presents selected Cybersecurity-related standards and provides an outlook on future challenges to Conformity Assessment in the digital transformation.
Standardization research is a fairly new and is a still-evolving field of research, with possibly major practical ramifications. This article presents a summary of the authors’ subjective views of the most pressing research topics in the field. These include, among others, standards (e.g. incorporation of ethical issues), the potential impact of standards, the corporate management of standardization and legal issues like Intellectual Property Rights (IPR). In addition, gaps have been identified with a respect to a basic understanding of standardization, suggesting a need for better education in the field.