PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 26, 2026Procedia Computer Science0 citationsOpen Access

ISO/IEC 27001:2022 in a Biotech SME: Open-Source Innovation Case Study in Taiwan

View Full Paper
JHJung-Hsiung HuangKCKuen-Tsann ChenTYTseng-Chang Yen

Key Points

  • The study aims to assess the implementation of ISO/IEC 27001:2022 in a biotech SME to enhance information security management.
  • Adopted a phased approach for ISO/IEC 27001 certification
  • Utilized open-source tools for security monitoring and training
  • Conducted a mixed-methods case study guided by theoretical frameworks
  • Achieved a 31% reduction in security incidents
  • Improved employee cybersecurity awareness by 40%
  • Increased customer satisfaction by 10 points
  • Total implementation cost was 35% below industry benchmarks

Abstract

This study explores the implementation of ISO/IEC 27001:2022 in a resource-constrained biotech small and medium enterprise (SME) in Taiwan. The company adopted a phased approach, achieving ISO/IEC 27001:2013 certification in April 2023 and transitioning to the 2022 standard by April 2025. By leveraging open-source tools for security monitoring, log management, and training, the company achieved a 31% reduction in security incidents, a 40% improvement in employee cybersecurity awareness, and a 10-point increase in customer satisfaction. The total implementation cost was approximately 35% below typical industry benchmarks. This mixed-methods case study, guided by a control classification framework (ACT–TRG–SCP) and interpreted through threat response, technology adoption, and institutional theories, provides a replicable roadmap for resource-limited SMEs to strengthen their Information Security Management System (ISMS). Limitations include reliance on internal auditing and biotech-specific applicability, suggesting the need for cross-industry research to enhance generalizability. The findings demonstrate that strategic use of open-source tools can enable robust ISMS compliance in high-stakes sectors.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Huang et al. (2026) studied this question.

synapsesocial.com/papers/69c4cd12fdc3bde448919020https://doi.org/10.1016/j.procs.2026.02.452
Ask AI
Helpful
Bookmark
Share
View Full Paper