Exploring the Adoption of the International Information Security Management System Standard ISO/IEC 27001 in Finland
Özmen, Gülfem; Heikkilä, Jussi; Ojanen, Ville (2026-06-16)
Publishers version
Özmen, Gülfem
Heikkilä, Jussi
Ojanen, Ville
16.06.2026
Journal of Standardisation
5
TU Delft OPEN Publishing
School of Engineering Science
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi-fe20260626104327
https://urn.fi/URN:NBN:fi-fe20260626104327
Tiivistelmä
This study examines the adoption of the ISO/IEC 27001 standard among firms in Finland by analyzing the websites of 97 ICT firms, 35 (36%) of which held certification of this standard. The findings show that certified firms communicate their certification through websites, annual reports, and press releases, and engage in cybersecurity-related activities. The results reveal substantial heterogeneity in how firms communicate certification and signal information security quality. ISO/IEC 27001 certification thus functions not only as a compliance mechanism but also as a signaling tool, the effectiveness of which depends on how firms deploy it across communication channels. A thematic analysis of annual reports and press releases identifies four key themes: resilience to cyberattacks, continuous improvement, regulatory compliance, and building trust and reputation. These findings further suggest that certification reflects not only signaling and institutional dynamics but also underlying organizational capabilities, pointing to additional theoretical dimensions for future research.
Lähdeviite
Özmen, G., Heikkilä, J., Ojanen, V. (2026). Exploring the Adoption of the International Information Security Management System Standard ISO/IEC 27001 in Finland. Journal of Standardisation, 5. https://doi.org/10.59490/jos.2026.8368
Alkuperäinen verkko-osoite
https://journals.open.tudelft.nl/jos/article/view/8368Kokoelmat
- Tieteelliset julkaisut [1857]
