Mapping and Integrating Security and Risk Standards: a Systematic Literature Review

被引:0
|
作者
Fernandes, Andre [1 ]
Cruz, Joao [1 ]
da Silva, Miguel Mira [1 ]
Pereira, Ruben [2 ]
机构
[1] Univ Lisbon, INOV INESC INOVACAO, Lisbon, Portugal
[2] Univ Inst Lisbon, ISCTE, Lisbon, Portugal
关键词
Mapping; Integration; Harmonization; Systematic Literature Review; Standards; Risk; Security; Business Continuity; MANAGEMENT; FRAMEWORK; ONTOLOGY; COBIT;
D O I
10.3897/jucs.111677
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Organizations are under increasing pressure to comply with various rules, standards, and policies in today's regulatory environment. Compliance controls are put in place to avoid legal or regulatory violations, which could lead to severe penalties, loss of reputation, and financial damages. However, these controls may have similar scopes and objectives, resulting in duplicated work and unnecessary costs for the organizations. To address this issue, researchers carry out the mapping and integration of these standards to avoid duplication, streamline compliance efforts, and identify best practices. Our work aims to improve the State -of -the -Art by exploring the main benefits and problems resulting from these processes, as well as identifying methods or artifacts that can be reused in the future. We focus on the fields of Risk, Security, and Business Continuity, as these are critical areas where compliance is crucial for organizations. Through our research, we have found that current methods of generating mapping artifacts are not only cumbersome to execute but also ineffective, as they output a single artifact without the reasoning behind it.
引用
收藏
页码:433 / 448
页数:16
相关论文
共 50 条
  • [1] A systematic literature review of mitigating cyber security risk
    Kamarudin S.
    Tang L.
    Bolong J.
    Adzharuddin N.A.
    Quality & Quantity, 2024, 58 (4) : 3251 - 3273
  • [2] Cyber Security Risk Management for Ports - A Systematic Literature Review
    Drummond, Barbara M.
    Machado, Raphael C. S.
    2021 IEEE INTERNATIONAL WORKSHOP ON METROLOGY FOR THE SEA (METROSEA 2021), 2021, : 406 - 411
  • [3] Integration of IT Governance and Security Risk Management: a Systematic Literature Review
    De Smet, Dieter
    Mayer, Nicolas
    INTERNATIONAL CONFERENCE ON INFORMATION SOCIETY (I-SOCIETY 2016), 2016, : 143 - 148
  • [4] A systematic literature review on AAOIFI standards
    El-Halaby, Sherif
    Aboul-Dahab, Sameh
    Bin Qoud, Nuha
    JOURNAL OF FINANCIAL REPORTING AND ACCOUNTING, 2021, 19 (02) : 133 - 183
  • [5] Integrating Service Design and Gamification: A Systematic Literature Mapping
    Conejo, Gabriel Guebarra
    Martins, Marcos Vinnicius
    Hounsell, Marcelo da Silva
    Gasparini, Isabela
    IEEE 21ST INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES (ICALT 2021), 2021, : 94 - 96
  • [6] Microservice security: a systematic literature review
    Berardi, Davide
    Giallorenzo, Saverio
    Mauro, Jacopo
    Melis, Andrea
    Montesi, Fabrizio
    Prandini, Marco
    PEERJ COMPUTER SCIENCE, 2022, 8
  • [7] Microservice security: a systematic literature review
    Berardi D.
    Giallorenzo S.
    Melis A.
    Prandini M.
    Mauro J.
    Montesi F.
    PeerJ Computer Science, 2022, 7
  • [8] Usable Security: A Systematic Literature Review
    Di Nocera, Francesco
    Tempestini, Giorgia
    Orsini, Matteo
    INFORMATION, 2023, 14 (12)
  • [9] Security Ontologies: A Systematic Literature Review
    Adach, Malina
    Hanninen, Kaj
    Lundqvist, Kristina
    ENTERPRISE DESIGN, OPERATIONS, AND COMPUTING, EDOC 2022, 2022, 13585 : 36 - 53
  • [10] Integrating disaster risk reduction and climate change adaptation: a systematic literature review
    Islam, Shafiqul
    Chu, Cordia
    Smart, James C. R.
    Liew, Leong
    CLIMATE AND DEVELOPMENT, 2020, 12 (03) : 255 - 267