Mapping and Integrating Security and Risk Standards: a Systematic Literature Review

被引:0
|
作者
Fernandes, Andre [1 ]
Cruz, Joao [1 ]
da Silva, Miguel Mira [1 ]
Pereira, Ruben [2 ]
机构
[1] Univ Lisbon, INOV INESC INOVACAO, Lisbon, Portugal
[2] Univ Inst Lisbon, ISCTE, Lisbon, Portugal
关键词
Mapping; Integration; Harmonization; Systematic Literature Review; Standards; Risk; Security; Business Continuity; MANAGEMENT; FRAMEWORK; ONTOLOGY; COBIT;
D O I
10.3897/jucs.111677
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Organizations are under increasing pressure to comply with various rules, standards, and policies in today's regulatory environment. Compliance controls are put in place to avoid legal or regulatory violations, which could lead to severe penalties, loss of reputation, and financial damages. However, these controls may have similar scopes and objectives, resulting in duplicated work and unnecessary costs for the organizations. To address this issue, researchers carry out the mapping and integration of these standards to avoid duplication, streamline compliance efforts, and identify best practices. Our work aims to improve the State -of -the -Art by exploring the main benefits and problems resulting from these processes, as well as identifying methods or artifacts that can be reused in the future. We focus on the fields of Risk, Security, and Business Continuity, as these are critical areas where compliance is crucial for organizations. Through our research, we have found that current methods of generating mapping artifacts are not only cumbersome to execute but also ineffective, as they output a single artifact without the reasoning behind it.
引用
收藏
页码:433 / 448
页数:16
相关论文
共 50 条
  • [21] Food security governance: a systematic literature review
    Jeroen J. L. Candel
    Food Security, 2014, 6 : 585 - 601
  • [22] BYOD security issues: a systematic literature review
    Ratchford, Melva
    El-Gayar, Omar
    Noteboom, Cherie
    Wang, Yong
    INFORMATION SECURITY JOURNAL, 2022, 31 (03): : 253 - 273
  • [23] INFORMATION SECURITY CULTURE: A SYSTEMATIC LITERATURE REVIEW
    Hassan, Noor Hafizah
    Ismail, Zuraini
    Maarop, Nurazean
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON COMPUTING & INFORMATICS, 2015, : 456 - 463
  • [24] A systematic literature review of blockchain cyber security
    Taylor, Paul J.
    Dargahi, Tooska
    Dehghantanha, Ali
    Parizi, Reza M.
    Choo, Kim-Kwang Raymond
    DIGITAL COMMUNICATIONS AND NETWORKS, 2020, 6 (02) : 147 - 156
  • [25] A systematic literature review of blockchain cyber security
    Paul JTaylor
    Tooska Dargahi
    Ali Dehghantanha
    Reza MParizi
    KimKwang Raymond Choo
    Digital Communications and Networks, 2020, 6 (02) : 147 - 156
  • [26] Security in Smart Toys: A Systematic Review of Literature
    Pontes, Lara
    Coutinho, Gustavo
    Hung, Patrick C. K.
    Yankson, Benjamin
    DISTRIBUTED, AMBIENT AND PERVASIVE INTERACTIONS, 2019, 11587 : 28 - 38
  • [27] Security Management Standards: A Mapping
    Haufe, Knut
    Colomo-Palacios, Ricardo
    Dzombeta, Srdan
    Brandis, Knud
    Stantchev, Vladimir
    INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS/INTERNATIONAL CONFERENCE ON PROJECT MANAGEMENT/INTERNATIONAL CONFERENCE ON HEALTH AND SOCIAL CARE INFORMATION SYSTEMS AND TECHNOLOGIES, CENTERIS/PROJMAN / HCIST 2016, 2016, 100 : 755 - 761
  • [28] A systematic literature review of communications standards in discrete manufacturing
    Ercan, Furkan
    Bega, Maximilian
    Kuhlenkoetter, Bernd
    PROCEEDINGS OF THE CONFERENCE ON PRODUCTION SYSTEMS AND LOGISTICS, CPSL 2023-2, 2023, : 80 - 89
  • [29] Analysing supply chain resilience: integrating the constructs in a concept mapping framework via a systematic literature review
    Ali, Abubakar
    Mahfouz, Amr
    Arisha, Amr
    SUPPLY CHAIN MANAGEMENT-AN INTERNATIONAL JOURNAL, 2017, 22 (01) : 16 - 39
  • [30] Information Security Risk Management in IT Outsourcing - A Quarter-century Systematic Literature Review
    Bhatti, Baber Majid
    Mubarak, Sameera
    Nagalingam, Sev
    JOURNAL OF GLOBAL INFORMATION TECHNOLOGY MANAGEMENT, 2021, 24 (04) : 259 - 298