Information security is considered as a concern for all organizations. “The total number of security
incidents reported to the CERT (Computer Emergency Response Team) rose from 2,412 in
1995 to 82,094 in 2002” (Purser, 2004). The use of IT standards could be one way to protect sensitive
information within an organization. This survey study explains the wide applicability of IT
standards in various sectors in the UAE, the advantages and disadvantages of using these standards,
and organizations’ future need for IT standards. Three cases studies in three contexts are
detailed. The first is on the Abu Dhabi Systems and Information Centre (ADSIC). Their program
is consistent with the ISO 27001 framework, and they have expanded it using additional management
processes. The second is on Injazat Data Systems. They used the integrated ISO 20000 -
ISO 27001 approach to mandate a high level of process control and managed service delivery.
The integrated approach supports faster and more effective business decisions, which are integral
to Injazat’s core goal. The third case study is on the security certification process at Abu Dhabi
Gas Industries Ltd. (GASCO). To summarize our findings, these three case studies can be used as
a practical guide to implement ISO 27001 within an organization. As this research indicates the
importance of applying standards within an organization therefore, producing graduates with that
knowledge in Information Security domain is required. Integrating ISO standards to IT curriculums
could be a future work for this study. We can also consider comparative studies globally in
terms of costs, company types, limitations, procedures and processes and advantages and disadvantages