The amount of information and the collective effort required for a company to win new business opportunities through formal tenders and bids has always been quite high. However, with a stronger focus nowadays on the protection of personal and sensitive data belonging to organisations and their clients, bidders are being pressurised to give even more information about their internal processes and procedures. At the same time, they need to provide clear answers and tangible evidence on how they deal with information governance and information security. Organisations wishing to win new business through tenders and bids are under pressure to give clear information on how they deal with information governance and security. This has become so important that an organisation issuing a tender might choose one supplier over another based solely on its compliance with applicable regulations or the fact it holds the ISO 27001 certification. Companies are therefore wondering if they should get certified, what compliance entails and what the implications of these ‘bureaucratic complications’ are. In any case, an information security review or internal audit can be a vital tool to enable a firm to understand its current maturity level and possible improvements as well as to answer lengthy and detailed security questionnaires, explains David Cowan of Plan-Net.
No takes yet. Share an insight, caveat, or question.
David Cowan (2011) studied this question.