Logo del repository
  1. Home
 
Opzioni

Information security and value creation: The performance implications of ISO/IEC 27001

Podrecca M.
•
Culot G.
•
Nassimbeni G.
•
Sartor M.
2022
  • journal article

Periodico
COMPUTERS IN INDUSTRY
Abstract
Although protecting information is the key challenge in a business environment characterized by increasing digitalization and connectivity, the impact of firms’ investments in information security on their financial performance is unclear. In this paper, we focus on ISO/IEC 27001 (i.e., the most renowned norm in the field and the fourth most widespread ISO standard) and analyze the relationship between the attainment of the certification and firms’ financial performance. We developed a set of theory-grounded hypotheses and tested them through a long-term event study complemented by an ordinary least squares regression on a dataset of 143 US-listed companies. The results indicate that the ISO/IEC 27001 certification is associated with improvements in profitability, labor productivity, and (partially) sales performance. The impact appears affected by the level of internationalization of the certified firm. The study contributes to the scientific debate on information security and certifications by developing the first large-scale empirical investigation based on secondary data on the financial implications of ISO/IEC 27001. Moreover, we further deepen the current knowledge on the effects of international management standards on firms’ performance thus enabling comparisons with other major management system standards.
DOI
10.1016/j.compind.2022.103744
Archivio
http://hdl.handle.net/11390/1229824
info:eu-repo/semantics/altIdentifier/scopus/2-s2.0-85134670927
https://ricerca.unityfvg.it/handle/11390/1229824
Diritti
closed access
Soggetti
  • Information security

  • International managem...

  • ISO

  • ISO 27001

  • ISO/IEC 27001

  • Management system sta...

google-scholar
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your nstitution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Realizzato con Software DSpace-CRIS - Estensione mantenuta e ottimizzata da 4Science

  • Impostazioni dei cookie
  • Informativa sulla privacy
  • Accordo con l'utente finale
  • Invia il tuo Feedback