Mapping and Integrating Security and Risk Standards: a Systematic Literature Review

被引:0
|
作者
Fernandes, Andre [1 ]
Cruz, Joao [1 ]
da Silva, Miguel Mira [1 ]
Pereira, Ruben [2 ]
机构
[1] Univ Lisbon, INOV INESC INOVACAO, Lisbon, Portugal
[2] Univ Inst Lisbon, ISCTE, Lisbon, Portugal
关键词
Mapping; Integration; Harmonization; Systematic Literature Review; Standards; Risk; Security; Business Continuity; MANAGEMENT; FRAMEWORK; ONTOLOGY; COBIT;
D O I
10.3897/jucs.111677
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Organizations are under increasing pressure to comply with various rules, standards, and policies in today's regulatory environment. Compliance controls are put in place to avoid legal or regulatory violations, which could lead to severe penalties, loss of reputation, and financial damages. However, these controls may have similar scopes and objectives, resulting in duplicated work and unnecessary costs for the organizations. To address this issue, researchers carry out the mapping and integration of these standards to avoid duplication, streamline compliance efforts, and identify best practices. Our work aims to improve the State -of -the -Art by exploring the main benefits and problems resulting from these processes, as well as identifying methods or artifacts that can be reused in the future. We focus on the fields of Risk, Security, and Business Continuity, as these are critical areas where compliance is crucial for organizations. Through our research, we have found that current methods of generating mapping artifacts are not only cumbersome to execute but also ineffective, as they output a single artifact without the reasoning behind it.
引用
收藏
页码:433 / 448
页数:16
相关论文
共 50 条
  • [31] A Systematic Literature Review of Empirical Methods and Risk Representation in Usable Privacy and Security Research
    Distler, Verena
    Fassl, Matthias
    Habib, Hana
    Krombholz, Katharina
    Lenzini, Gabriele
    Lallemand, Carine
    Cranor, Lorrie Faith
    Koenig, Vincent
    ACM TRANSACTIONS ON COMPUTER-HUMAN INTERACTION, 2021, 28 (06)
  • [32] Security Risk Assessment on Cloud: A Systematic Mapping Study
    Annunziata, Giusy
    Sheykina, Alexandra
    Palomba, Fabio
    De Lucia, Andrea
    Catolino, Gemma
    Ferrucci, Filomena
    PROCEEDINGS OF 2024 28TH INTERNATION CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, EASE 2024, 2024, : 604 - 613
  • [33] A systematic review of the literature on integrating sustainability into engineering curricula
    Thurer, Matthias
    Tomasevic, Ivan
    Stevenson, Mark
    Qu, Ting
    Huisingh, Don
    JOURNAL OF CLEANER PRODUCTION, 2018, 181 : 608 - 617
  • [34] Security Ontology for Adaptive Mapping of Security Standards
    Ramanauskaite, S.
    Olifer, D.
    Goranin, N.
    Cenys, A.
    INTERNATIONAL JOURNAL OF COMPUTERS COMMUNICATIONS & CONTROL, 2013, 8 (06) : 878 - 890
  • [35] Use of Intervention Mapping for Occupational Risk Prevention and Health Promotion: A Systematic Review of Literature
    Bakhuys Roozeboom, Maartje C.
    Wiezer, Noortje M.
    Boot, Cecile R. L.
    Bongers, Paulien M.
    Schelvis, Roosmarijn M. C.
    INTERNATIONAL JOURNAL OF ENVIRONMENTAL RESEARCH AND PUBLIC HEALTH, 2021, 18 (04) : 1 - 19
  • [36] Not at Imminent Risk A Systematic Literature Review
    Monaghan, Kate
    Harris, Martin
    CRISIS-THE JOURNAL OF CRISIS INTERVENTION AND SUICIDE PREVENTION, 2015, 36 (06) : 459 - 463
  • [37] Security Issues in Fog Environment: A Systematic Literature Review
    Jasleen Kaur
    Alka Agrawal
    Raees Ahmad Khan
    International Journal of Wireless Information Networks, 2020, 27 : 467 - 483
  • [38] Security and Privacy for Big Data: A Systematic Literature Review
    Nelson, Boel
    Olovsson, Tomas
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 3693 - 3702
  • [39] Security Analysis of the Internet of Things: A Systematic Literature Review
    Martinez, Juan
    Mejia, Jezreel
    Munoz, Mirna
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON SOFTWARE PROCESS IMPROVEMENT (CIMPS 2016): APPLICATIONS IN SOFTWARE ENGINEERING, 2016,
  • [40] On the Security Aspects of Internet of Things: A Systematic Literature Review
    Macedo, Evandro L. C.
    de Oliveira, Egberto A. R.
    Silva, Fabio H.
    Mello Jr, Rui R.
    Franca, Felipe M. G.
    Delicato, Flavia C.
    de Rezende, Jose F.
    de Moraes, Luis F. M.
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2019, 21 (05) : 444 - 457