Impact of Information Security Management System on Firm Financial Performance: Perspective of Corporate Reputation and Branding — Oak Academic Publishing
Research ArticleOpen AccessGoogle Scholar indexed
Impact of Information Security Management System on Firm Financial Performance: Perspective of Corporate Reputation and Branding
Center of Security Convergence & e-Governance, Inha University, Incheon, Korea
,
Graduate School of Business Administration, Ajou University, Suwon, Republic of Korea
1 Center of Security Convergence & e-Governance, Inha University, Incheon, Korea
2 Graduate School of Business Administration, Ajou University, Suwon, Republic of Korea
The immense organizational emphasis on information technology (IT), combined with the growing impact of information security issues, has inflated information security to the top list of management’s priorities. The ISO 27001 standard defines the requirements for an effective information security man agement system (ISMS). However, the implementation of ISMS not onl y maximizes firm performance directly, but it can also have a significant impact in different contexts. We investigated whether ISMS implementation can benefit organizations financially by contributing to corporate reputation and branding in this study. With samples from 171 Pakistani firms, we examined firm performance after ISMS ISO 27001 certification. Compatible with our expectations, we discovered strong evidence that ISMS implementation benefited c ertified firms in terms of high corporate reputation, brand and bran ding, and financial performance.
KeywordsInformation Security Management System (ISMS)ISO 27001Corporate ReputationBrand and BrandingFirm Performance
Abdillah, W., & Hartono, J. (2015). Partial Least Square (PLS): Alternatif Structural Equation Modeling (SEM) Dalam Penelitian Bisnis. Yogyakarta: Penerbit Andi, 22, 103-150.
Alqahtani, F. H. (2017). Developing an Information Security Policy: A Case Study Approach. Procedia Computer Science, 124, 691-697. https://doi.org/10.1016/j.procs.2017.12.206
Arshad, R., Othman, S., & Othman, R. (2012). Islamic Corporate Social Responsibility, Corporate Reputation and Performance. International Journal of Economics and Management Engineering, 6, 643-647.
Atkinson, J. S., Mitchell, J. E., Rio, M., & Matich, G. (2018). Your WiFi Is Leaking: What Do Your Mobile Apps Gossip about You? Future Generation Computer Systems, 80, 546-557. https://doi.org/10.1016/j.future.2016.05.030
Bakar, Z. A., Yaacob, N. A., & Udin, Z. M. (2015). The Effect of Business Continuity Management Factors on Organizational Performance: A Conceptual Framework. International Journal of Economics and Financial Issues, 5, 128-134.
Barnett, M. L., Jermier, J. M., & Lafferty, B. A. (2006). Corporate Reputation: The Definitional Landscape. Corporate Reputation Review, 9, 26-38. https://doi.org/10.1057/palgrave.crr.1550012
Barney, J. B. (2001). Resource-Based Theories of Competitive Advantage: A Ten-Year Retrospective on the Resource-Based View. Journal of Management, 27, 643-650. https://doi.org/10.1177/014920630102700602
Baskerville, R. (1991). Risk Analysis: An Interpretive Feasibility Tool in Justifying Information Systems Security. European Journal of Information Systems, 1, 121-130. https://doi.org/10.1057/ejis.1991.20
Bokhari, S. A. A., & Aftab, M. (2022). Personality Traits and Social Loafing among Employees Working in Teams at Small and Medium Enterprises: A Cultural Perspective Data from Emerging Economies. Data in Brief, 42, Article ID: 108085. https://doi.org/10.1016/j.dib.2022.108085
Bokhari, S. A. A., & Myeong, S. (2022). Use of Artificial Intelligence in Smart Cities for Smart Decision-Making: A Social Innovation Perspective. Sustainability, 14, Article No. 620. https://doi.org/10.3390/su14020620
Bokhari, S. A. A., Aftab, M., & Shahid, M. (2021). Political Instability and Inward Foreign Direct Investment: The Perspective of Government Corruption from an Emerging Economy. Industry Promotion Research, 6, 69-81.
Calder, A. (2017). Nine Steps to Success: An ISO 27001 Implementation Overview. IT Governance Ltd. https://doi.org/10.2307/j.ctt1wn0skw
Campbell, J. L. (2007). Why Would Corporations Behave in Socially Responsible Ways? An Institutional Theory of Corporate Social Responsibility. Academy of Management Review, 32, 946-967. https://doi.org/10.5465/amr.2007.25275684
Chang, H. (2013). Is ISMS for Financial Organizations Effective on Their Business? Mathematical and Computer Modelling, 58, 79-84. https://doi.org/10.1016/j.mcm.2012.07.018
Choong, P., Hutton, E., Richardson, P. S., & Rinaldo, V. (2017). Protecting the Brand: Evaluating the Cost of Security Breach from a Marketer’s Perspective. Journal of Marketing Development and Competitiveness, 11, 59-68.
Chun, R. (2005). Corporate Reputation: Meaning and Measurement. International Journal of Management Reviews, 7, 91-109. https://doi.org/10.1111/j.1468-2370.2005.00109.x
Coaffee, J., & Van Ham, P. (2008). ‘Security Branding’: The Role of Security in Marketing the City, Region or State. Place Branding and Public Diplomacy, 4, 191-195. https://doi.org/10.1057/pb.2008.11
Dao, T. K., Tapanainen, T. J., Nguyen, H. T. T., Nguyen, T. H., & Nguyen, N. D. (2017). Information Safety, Corporate Image, and Intention to Use Online Services: Evidence from Travel Industry in Vietnam. In 23rd Americas Conference on Information Systems (AMCIS 2017): A Tradition of Innovation (pp. 147-156). Association for Information Systems.
De Chernatony, L. (1999). Brand Management through Narrowing the Gap between Brand Identity and Brand Reputation. Journal of Marketing Management, 15, 157-179. https://doi.org/10.1362/026725799784870432
Eloff, M. M., & Von Solms, S. H. (2000). Information Security Management: An Approach to Combine Process Certification and Product Evaluation. Computers & Security, 19, 698-709. https://doi.org/10.1016/S0167-4048(00)08019-6
Erceg-Hurn, D. M., & Mirosevich, V. M. (2008). Modern Robust Statistical Methods: An Easy Way to Maximize the Accuracy and Power of Your Research. American Psychologist, 63, 591-601. https://doi.org/10.1037/0003-066X.63.7.591
Farquhar, P. H. (1994). Strategic Challenges for Branding. Marketing Management, 3, 8-15.
Fombrun, C. J., Ponzi, L. J., & Newburry, W. (2015). Stakeholder Tracking and Analysis: The RepTrak® System for Measuring Corporate Reputation. Corporate Reputation Review, 18, 3-24. https://doi.org/10.1057/crr.2014.21
Fournier, S. (1998). Consumers and Their Brands: Developing Relationship Theory in Consumer Research. Journal of Consumer Research, 24, 343-373. https://doi.org/10.1086/209515
Fryxell, G. E., & Wang, J. (1994). The Fortune Corporate Reputation Index: Reputation for What? Journal of Management, 20, 1-14. https://doi.org/10.1177/014920639402000101
Goel, S., & Shawky, H. A. (2009). Estimating the Market Impact of Security Breach Announcements on Firm Values. Information & Management, 46, 404-410. https://doi.org/10.1016/j.im.2009.06.005
Gwebu, K. L., Wang, J., & Wang, L. (2018). The Role of Corporate Reputation and Crisis Response Strategies in Data Breach Management. Journal of Management Information Systems, 35, 683-714. https://doi.org/10.1080/07421222.2018.1451962
Hampf, A., & Lindberg-Repo, K. (2011). Branding: The Past, Present, and Future: A Study of the Evolution and Future of Branding. Hanken School of Economics.
Han, J., Kim, Y. J., & Kim, H. (2017). An Integrative Model of Information Security Policy Compliance with Psychological Contract: Examining a Bilateral Perspective. Computers & Security, 66, 52-65. https://doi.org/10.1016/j.cose.2016.12.016
Hausken, K. (2006). Returns to Information Security Investment: The Effect of Alternative Information Security Breach Functions on Optimal Investment and Sensitivity to Vulnerability. Information Systems Frontiers, 8, 338-349. https://doi.org/10.1007/s10796-006-9011-6
He, W., Liu, C., Lu, J., & Cao, J. (2015). Impacts of ISO 14001 Adoption on Firm Performance: Evidence from China. China Economic Review, 32, 43-56. https://doi.org/10.1016/j.chieco.2014.11.008
He, Y., & Lai, K. K. (2014). The Effect of Corporate Social Responsibility on Brand Loyalty: The Mediating Role of Brand Image. Total Quality Management & Business Excellence, 25, 249-263. https://doi.org/10.1080/14783363.2012.661138
Holt, D. B., & Holt, D. B. (2004). How Brands Become Icons: The Principles of Cultural Branding. Harvard Business Press.
Homburg, C., Klarmann, M., & Schmitt, J. (2010). Brand Awareness in Business Markets: When Is It Related to Firm Performance? International Journal of Research in Marketing, 27, 201-212. https://doi.org/10.1016/j.ijresmar.2010.03.004
Hsu, C., Wang, T., & Lu, A. (2016). The Impact of ISO 27001 Certification on Firm Performance. In 2016 49th Hawaii International Conference on System Sciences (HICSS) (pp. 4842-4848). IEEE. https://doi.org/10.1109/HICSS.2016.600
Hung, W. H., Chang, I. C., Chen, Y., & Ho, Y. L. (2019). Aligning 4C strategy with Social Network Applications for CRM Performance. Journal of Global Information Management (JGIM), 27, 93-110. https://doi.org/10.4018/JGIM.2019010105
Iwu-Egwuonwu, R. C. (2010). Corporate Reputation & Firm Performance: Empiricial Literature Evidence. International Journal of Business and Management, 6, 197-206. https://doi.org/10.2139/ssrn.1659595
Jannah, M., Fahlevi, M., Paulina, J., Nugroho, B. S., Purwanto, A., Subarkah, M. A., Kurniati, E., Wibowo, T. S., Kalbuana, K. N., & Cahyono, Y. (2020). Effect of ISO 9001, ISO 45001 and ISO 14000 toward Financial Performance of Indonesian Manufacturing. Systematic Reviews in Pharmacy, 11, 894-902.
Kamdjoug, J. R. K., Tewamba, H. J. N., & Wamba, S. F. (2018). IT Capabilities, Firm Performance and the Mediating Role of ISRM: A Case Study from a Developing Country. Business Process Management Journal, 25, 476-494. https://www.emerald.com/insight/content/doi/10.1108/BPMJ-11-2017-0297/full/html
Kapferer, J. N. (2008). The New Strategic Brand Management: Creating and Sustaining Brand Equity Long Term. Kogan Page Publishers.
Ki-Aries, D., & Faily, S. (2017). Persona-Centred Information Security Awareness. Computers & Security, 70, 663-674. https://doi.org/10.1016/j.cose.2017.08.001
Kitchin, T. (2003). Corporate Social Responsibility: A Brand Explanation. Journal of Brand Management, 10, 312-326. https://doi.org/10.1057/palgrave.bm.2540127
Lai, C. S., Chiu, C. J., Yang, C. F., & Pai, D. C. (2010). The Effects of Corporate Social Responsibility on Brand Performance: The Mediating Effect of Industrial Brand Equity and Corporate Reputation. Journal of Business Ethics, 95, 457-469. https://doi.org/10.1007/s10551-010-0433-1
Laufer, D., & Coombs, W. T. (2006). How Should a Company Respond to a Product Harm Crisis? The Role of Corporate Reputation and Consumer-Based Cues. Business Horizons, 49, 379-385. https://doi.org/10.1016/j.bushor.2006.01.002
Lee, J., & Roh, J. J. (2012). Revisiting Corporate Reputation and Firm Performance Link. Benchmarking: An International Journal, 19, 649-664. https://doi.org/10.1108/14635771211258061
Lele, Q., & Lihua, K. (2016). Technical Framework Design of Safety Production Information Management Platform for Chemical Industrial Parks Based on Cloud Computing and the Internet of Things. International Journal of Grid and Distributed Computing, 9, 299-314. https://doi.org/10.14257/ijgdc.2016.9.6.28
Marquardt, R., Makens, J., & Larzelere, H. (1965). Measuring the Utility Added by Branding and Grading. Journal of Marketing Research, 2, 45-50. https://doi.org/10.1177/002224376500200106
Martínez, P., Pérez, A., & Del Bosque, I. R. (2014). CSR Influence on Hotel Brand Image and Loyalty. Academia Revista Latinoamericana de Administración, 27, 267-283. https://doi.org/10.1108/ARLA-12-2013-0190
Mastoi, R. B., Khan, Z., Mastoi, S. et al. (2021). ISO Certifications in Pakistan: Patterns & Application. International Journal of Management, 12, 403-415.
McGuire, J. B., Schneeweis, T., & Branch, B. (1990). Perceptions of Firm Quality: A Cause or Result of Firm Performance. Journal of Management, 16, 167-180. https://doi.org/10.1177/014920639001600112
Meixner, F., & Buettner, R. (2012). Trust as an Integral Part for Success of Cloud Computing. In ICIW 2012 Proceedings (pp. 207-214).
Menon, N. M., & Siponen, M. T. (2020). Executives’ Commitment to Information Security: Interaction between the Preferred Subordinate Influence Approach (PSIA) and Proposal Characteristics. ACM SIGMIS Database: The DATABASE for Advances in Information Systems, 51, 36-53. https://doi.org/10.1145/3400043.3400047
Moghe, P., Gehani, N., & Smith, P. T. (2014). Enterprise Information Asset Protection through Insider Attack Specification, Monitoring and Mitigation. US8880893B2.
Moore, K., & Reid, S. (2008). The Birth of Brand: 4000 Years of Branding. Business History, 50, 419-432. https://doi.org/10.1080/00076790802106299
Mukundan, N., & Sai, L. P. (2014). Perceived Information Security of Internal Users in Indian IT Services Industry. Information Technology and Management, 15, 1-8. https://doi.org/10.1007/s10799-013-0156-y
Nechai, A., Pavlova, E., Batova, T., & Petrov, V. (2020). Implementation of Information Security System in Service and Trade. IOP Conference Series: Materials Science and Engineering, 940, Article ID: 012048. https://doi.org/10.1088/1757-899X/940/1/012048
Neubauer, T., Ekelhart, A., & Fenz, S. (2008). Interactive Selection of ISO 27001 Controls under Multiple Objectives. In IFIP International Information Security Conference (pp. 477-491).
Park, C. W., Eisingerich, A. B., Pol, G., & Park, J. W. (2013). The Role of Brand Logos in Firm Performance. Journal of Business Research, 66, 180-187. https://doi.org/10.1016/j.jbusres.2012.07.011
Peng, J., Quan, J., & Peng, L. (2019). It Application Maturity, Management Institutional Capability and Process Management Capability. Journal of Organizational and End User Computing (JOEUC), 31, 61-85. https://doi.org/10.4018/JOEUC.2019010104
Rastogi, R., & von Solms, R. (2012). Information Security Service Branding—Beyond Information Security Awareness. Systemics, Cybernetics and Informatics, 10, 54-59.
Sammut-Bonnici, T. (2014). Brand and Branding. Wiley Encyclopedia of Management. https://doi.org/10.1002/9781118785317.weom120161
Sato, H., Kanai, A., & Tanimoto, S. (2010). A Cloud Trust Model in a Security Aware Cloud. In 2010 10th IEEE/IPSJ International Symposium on Applications and the Internet (pp. 121-124). IEEE. https://doi.org/10.1109/SAINT.2010.13
Sharma, N., & Dash, P. K. (2012). Effectiveness of ISO 27001, as an Information Security Management System: An Analytical Study of Financial Aspects. Far East Journal of Psychology and Business, 9, 42-55.
Smith, S., Winchester, D., Bunker, D., & Jamieson, R. (2010). Circuits of Power: A Study of Mandated Compliance to an Information Systems Security “De Jure” Standard in a Government Organization. MIS Quarterly, 34, 463-486. https://doi.org/10.2307/25750687
Susanto, H., Almunawar, M. N., & Tuan, Y. C. (2011). Information Security Management System Standards: A Comparative Study of the Big Five. International Journal of Electrical Computer Sciences IJECSIJENS, 11, 23-29.
Tewamba, H. N., Kamdjoug, J. R. K., Bitjoka, G. B., Wamba, S. F., & Bahanag, N. N. M. (2019). Effects of Information Security Management Systems on Firm Performance. American Journal of Operations Management and Information Systems, 4, 99-108. https://doi.org/10.11648/j.ajomis.20190403.15
Tipton, H. F., & Krause, M. (2007). Information Security Management Handbook. CRC Press. https://doi.org/10.1201/9781439833032
Velasco, J., Ullauri, R., Pilicita, L., Jácome, B., Saa, P., & Moscoso-Zea, O. (2018). Benefits of Implementing an ISMS According to the ISO 27001 Standard in the Ecuadorian Manufacturing Industry. In 2018 International Conference on Information Systems and Computer Science (INCISCOS) (pp. 294-300). IEEE. https://doi.org/10.1109/INCISCOS.2018.00049
Wu, C. H., & Tsai, S. B. (2018). Using DEMATEL-Based ANP Model to Measure the Successful Factors of E-Commerce. In Intelligent Systems: Concepts, Methodologies, Tools, and Applications (pp. 1122-1138). IGI Global. https://doi.org/10.4018/978-1-5225-5643-5.ch047
Wu, W., Shi, K., Wu, C. H., & Liu, J. (2021). Research on the Impact of Information Security Certification and Concealment on Financial Performance: Impact of ISO 27001 and Concealment on Performance. Journal of Global Information Management (JGIM), 30, 1-16. https://doi.org/10.4018/JGIM.20220701.oa2
Yaeger, M. L. et al. (2015). Information Security: Obligations and Expectations. Schulte Roth & Zabel.