The ISO/IEC 27001 information security management standard: literature review and theory-based research agenda

被引:33
|
作者
Culot, Giovanna [1 ]
Nassimbeni, Guido [1 ]
Podrecca, Matteo [1 ]
Sartor, Marco [1 ]
机构
[1] Univ Udine, Polytech Dept Engn & Architecture, Udine, Italy
来源
TQM JOURNAL | 2021年 / 33卷 / 07期
关键词
ISO; IEC; 27001; Information security; Systematic literature review; Management system standards; SYSTEM STANDARDS; RISK-MANAGEMENT; CERTIFICATION; INTEGRATION; PERFORMANCE; FRAMEWORK; QUALITY; IMPACT; IMPLEMENTATION; ORGANIZATIONS;
D O I
10.1108/TQM-09-2020-0202
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
PurposeAfter 15 years of research, this paper aims to present a review of the academic literature on the ISO/IEC 27001, the most renowned standard for information security and the third most widespread ISO certification. Emerging issues are reframed through the lenses of social systems thinking, deriving a theory-based research agenda to inspire interdisciplinary studies in the field.Design/methodology/approachThe study is structured as a systematic literature review.FindingsResearch themes and sub-themes are identified on five broad research foci: relation with other standards, motivations, issues in the implementation, possible outcomes and contextual factors.Originality/valueThe study presents a structured overview of the academic body of knowledge on ISO/IEC 27001, providing solid foundations for future research on the topic. A set of research opportunities is outlined, with the aim to inspire future interdisciplinary studies at the crossroad between information security and quality management. Managers interested in the implementation of the standard and policymakers can find an overview of academic knowledge useful to inform their decisions related to implementation and regulatory activities.
引用
收藏
页码:76 / 105
页数:30
相关论文
共 50 条
  • [21] Tailoring ISO/IEC 27001 for SMEs: A Guide to Implement an Information Security Management System in Small Settings
    Valdevit, Thierry
    Mayer, Nicolas
    Barafort, Beatrix
    [J]. SOFTWARE PROCESS IMPROVEMENT, PROCEEDINGS, 2009, 42 : 201 - 212
  • [22] INTEGRATING THE INFORMATION SECURITY MANAGEMENT SYSTEM (ISO/IEC 27001) WITH OTHER MANAGEMENT SYSTEMS: A CASE STUDY IN A PHARMACEUTICAL ORGANISATION
    Oliveira, Rui
    Silva, Rui
    Rebelo, Manuel Ferreira
    [J]. IRF2016: 5TH INTERNATIONAL CONFERENCE INTEGRITY-RELIABILITY-FAILURE, 2016, : 843 - 844
  • [23] THEORETICAL AND PRACTICAL CONSIDERATIONS REGARDING THE INFORMATION SECURITY MANAGEMENT SYSTEM WITHIN ORGANIZATIONS IN CONCORDANCE WITH THE NEW INTERNATIONAL STANDARD ISO/IEC 27001:2013
    Tiganoaia, Bogdan
    [J]. GLOBALIZATION AND INTERCULTURAL DIALOGUE: MULTIDISCIPLINARY PERSPECTIVES - ECONOMY AND MANAGEMENT, 2014, : 62 - 68
  • [24] United Nations Global Compact: Literature review and theory-based research agenda
    Orzes, Guido
    Moretto, Antonella Maria
    Ebrahimpour, Maling
    Sartor, Marco
    Moro, Mattia
    Rossi, Matteo
    [J]. JOURNAL OF CLEANER PRODUCTION, 2018, 177 : 633 - 654
  • [25] Goal- Based Establishment of an Information Security Management System Compliant to ISO 27001
    Beckers, Kristian
    [J]. SOFSEM 2014: THEORY AND PRACTICE OF COMPUTER SCIENCE, 2014, 8327 : 102 - 113
  • [26] IMPROVING THE SECURITY OF LIBRARY-INFORMATION SYSTEM BY APPLYING STANDARD ISO 27001
    Jamandilovic, Stefan
    Stojanovic, Miroljub
    [J]. BOSNIACA-JOURNAL OF THE NATIONAL AND UNIVERSITY LIBRARY OF BOSNIA AND HERZEGOVINA, 2018, (23): : 95 - 98
  • [27] Evaluation of the Degree of Knowledge and Implementation of Information Security Management Systems, based of the NCh-ISO 27001 Standard, in Health Institutions
    Rienzo, Antonio
    Bustamante, Miguel
    Aravena, Camilo
    Lefranc, Gaston
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION/XXIII CONGRESS OF THE CHILEAN ASSOCIATION OF AUTOMATIC CONTROL (ICA-ACCA), 2018,
  • [28] The Evaluation of the Electronic Services with Accordance to IT-security Requirements Based on ISO/IEC 27001
    Livshitz, Ilya I.
    Nikiforova, Kseniya A.
    Lontsikh, Pavel A.
    Karaseva, Viktoria A.
    [J]. PROCEEDINGS OF THE 2016 IEEE CONFERENCE ON QUALITY MANAGEMENT, TRANSPORT AND INFORMATION SECURITY, INFORMATION TECHNOLOGIES (IT&MQ&IS), 2016,
  • [29] Analysis of factors that inhibiting implementation of Information Security Management System (ISMS) based on ISO 27001
    Tatiara, R.
    Fajar, A. N.
    Siregar, B.
    Gunawan, W.
    [J]. 2ND INTERNATIONAL CONFERENCE ON COMPUTING AND APPLIED INFORMATICS 2017, 2018, 978
  • [30] Assessment of ISMS Based On Standard ISO/IEC 27001:2013 at DISKOMINFO Depok City
    Nurbojatmiko
    Susanto, Aries
    Shobariah, Euis
    [J]. 2016 4TH INTERNATIONAL CONFERENCE ON CYBER AND IT SERVICE MANAGEMENT, 2016, : 43 - 48