Significance of ISO/IEC 27001 in the Implementation of Governance, Risk and Compliance

Authors

  • Sanskriti Choubey Master of Science in Cyber Law and Information Security, National Law Institute University, Bhopal, India
  • Astitwa Bhargava Rajeev Gandhi National Cyber Law Centre, National Law Institute University, Bhopal, India

Keywords:

ISO/IEC 27001:2013, GRC, ISMS, Risk Management, IT Governance

Abstract

In organisations, ‘Governance’, ‘Risk’ and ‘Compliance’ (GRC) are among the basic and strongest pillars that work together for the purpose of assuring organizations in meeting their objectives through effective utilization of the available people, process and technology. It is challenging task for most enterprises for sustaining Information Security GRC program with the evolving governance needs, changing risk environment and multiple compliance requirements. ISO 27001:2013 encompasses all the goals of GRC under its Information Security Management System (ISMS) framework through which an effective GRC framework could be established and maintained. In this research paper, researcher have established the relationship between ISO 27001:2013 and GRC while discussing the standard along with GRC objectives.

 

References

Ernest N Young Company “Implementing-a-governance-risk-and-compliance-program “

Risk & Compliance (GRC) Institute for Software Technology and Interactive Systems “A Frame of Reference for Research of Integrated Governance”.

EMC Corporation “The case for GRC –addressing the top 10 GRC challenges”- white paper.

Downloads

Published

2018-04-30

How to Cite

[1]
S. Choubey and A. Bhargava, “Significance of ISO/IEC 27001 in the Implementation of Governance, Risk and Compliance”, Int. J. Sci. Res. Net. Sec. Comm., vol. 6, no. 2, pp. 30–33, Apr. 2018.

Issue

Section

Review Article

Similar Articles

1 2 3 4 5 > >> 

You may also start an advanced similarity search for this article.