ADOPTION OF THE INFORMATION SECURITY MANAGEMENT SYSTEM STANDARD ISO/IEC 27001: A STUDY AMONG GERMAN ORGANIZATIONS

被引:0
|
作者
Mirtsch, Mona [1 ,2 ]
机构
[1] Bundesanstalt Mat Forsch & Prufung BAM, Berlin, Germany
[2] Tech Univ Berlin, Chair Innovat Econ, Berlin, Germany
关键词
ISO/IEC; 27001; Management system standard; Information security; QI-FoKuS; Certification; DIFFUSION; ISO-9000; PERFORMANCE; ISO-14001; BENEFITS; QUALITY;
D O I
10.24874/IJQR17.03-08
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Against the backdrop of numerous security breaches and cyber-attacks, organizations need to take measures to secure their data and information. However, the well-known security has shown a lower adoption rate - in terms of annual ISO survey data - than was previously expected by scholars and practitioners. Through the lens of Rogers' diffusion of innovation theory, we consider the adoption of ISO/IEC 27001 as a 'preventive innovation' and aim to identify factors that help gain a better understanding of its adoption. Therefore, we conducted a survey among German organizations on the use and impact of management system standards, explicitly distinguishing between organizations that implement ISO/IEC 27001 and those that are additionally certified against this standard. This study provides insights and contributes to an advanced understanding of motives, impacts, barriers, and useful measures to increase adoption of ISO/IEC 27001. Our findings may be useful to organizations considering the adoption of this management system standard, to certification bodies providing certification services, and to policymakers seeking means to improve information security in organizations.
引用
收藏
页码:747 / 768
页数:22
相关论文
共 50 条
  • [41] Extending unified theory of acceptance and use of technology with ISO/IEC 27001 security standard to investigate factors influencing Bring Your Own Device adoption in South Africa
    Mayayise, Thembekile
    [J]. SOUTH AFRICAN JOURNAL OF INFORMATION MANAGEMENT, 2021, 23 (01):
  • [42] Using Security Requirements Engineering Approaches to Support ISO 27001 Information Security Management Systems Development and Documentation
    Beckers, Kristian
    Fassbender, Stephan
    Heisel, Maritta
    Schmidt, Holger
    [J]. 2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 242 - 248
  • [43] Policies based on ISO 27001: 2013 and its influence on information security management in municipalities of Peru
    Bustamante Garcia, Shonerly
    Valles Coral, Miguel Angel
    Cuellar Rodriguez, Immer Elias
    Levano Rodriguez, Danny
    [J]. ENFOQUE UTE, 2021, 12 (02): : 69 - 79
  • [44] Security Characteristic Evaluation Based On ISO/IEC 25023 Quality Model, Case Study: Laboratory Management Information System
    Aziz, M. Nasrul
    Sapta, Irit Maulana
    Rochimah, Siti
    [J]. 2018 ELECTRICAL POWER, ELECTRONICS, COMMUNICATIONS, CONTROLS, AND INFORMATICS SEMINAR (EECCIS), 2018, : 332 - 336
  • [45] Information security failures identified and measured - ISO/IEC 27001:2013 controls ranked based on GDPR penalty case analysis
    Suorsa, M.
    Helo, P.
    [J]. INFORMATION SECURITY JOURNAL, 2024, 33 (03): : 285 - 306
  • [46] General Considerations on Risk Management and Information System Security Assessment According to ISO/IEC 27005:2011 and ISO 31000: 2009 Standards
    Firoiu, Marian
    [J]. QUALITY-ACCESS TO SUCCESS, 2015, 16 (149): : 93 - 97
  • [47] RoadMap web system for project management in the ISO/IEC 29110 standard.
    Zapata-Sanchez, Jose D. J.
    Armendariz-Rodriguez, Daniel A.
    Ordonez-Gutierrez, Mario C.
    Acuna-Cid, Hector A.
    Torres-Hernandez, Mayra A.
    [J]. 2023 12TH INTERNATIONAL CONFERENCE ON SOFTWARE PROCESS IMPROVEMENT, CIMPS 2023, 2023, : 42 - 50
  • [48] Combining ITIL, COBIT and ISO/IEC 27002 for structuring comprehensive information technology for management in organizations
    Gehrmann, Maico
    [J]. NAVUS-REVISTA DE GESTAO E TECNOLOGIA, 2012, 2 (02): : 66 - 77
  • [49] The Assessment of Information Security Management Process Capability using ISO/IEC 33072:2016 (Case Study in Statistics Indonesia)
    Rimawati, Yeni
    Sutikno, Sarwono
    [J]. PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY SYSTEMS AND INNOVATION (ICITSI), 2016,
  • [50] Designing Recommendations and Road Map of Governance for Quality Management System of Online SKCK Based on Information Security Using ISO 9001: 2015 and ISO 27001: 2013 (Case Study: Ditintelkam Polda ABC)
    Putra, Prima Pringgo
    Arman, Arry Akhmad
    Edward, Ian Joseph Matheus
    Shalannanda, Wervyan
    [J]. PROCEEDING OF 14TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATION SYSTEMS, SERVICES, AND APPLICATIONS (TSSA), 2020,