The ISO/IEC 27001 information security management standard: literature review and theory-based research agenda

被引:33
|
作者
Culot, Giovanna [1 ]
Nassimbeni, Guido [1 ]
Podrecca, Matteo [1 ]
Sartor, Marco [1 ]
机构
[1] Univ Udine, Polytech Dept Engn & Architecture, Udine, Italy
来源
TQM JOURNAL | 2021年 / 33卷 / 07期
关键词
ISO; IEC; 27001; Information security; Systematic literature review; Management system standards; SYSTEM STANDARDS; RISK-MANAGEMENT; CERTIFICATION; INTEGRATION; PERFORMANCE; FRAMEWORK; QUALITY; IMPACT; IMPLEMENTATION; ORGANIZATIONS;
D O I
10.1108/TQM-09-2020-0202
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
PurposeAfter 15 years of research, this paper aims to present a review of the academic literature on the ISO/IEC 27001, the most renowned standard for information security and the third most widespread ISO certification. Emerging issues are reframed through the lenses of social systems thinking, deriving a theory-based research agenda to inspire interdisciplinary studies in the field.Design/methodology/approachThe study is structured as a systematic literature review.FindingsResearch themes and sub-themes are identified on five broad research foci: relation with other standards, motivations, issues in the implementation, possible outcomes and contextual factors.Originality/valueThe study presents a structured overview of the academic body of knowledge on ISO/IEC 27001, providing solid foundations for future research on the topic. A set of research opportunities is outlined, with the aim to inspire future interdisciplinary studies at the crossroad between information security and quality management. Managers interested in the implementation of the standard and policymakers can find an overview of academic knowledge useful to inform their decisions related to implementation and regulatory activities.
引用
收藏
页码:76 / 105
页数:30
相关论文
共 50 条
  • [31] Policies based on ISO 27001: 2013 and its influence on information security management in municipalities of Peru
    Bustamante Garcia, Shonerly
    Valles Coral, Miguel Angel
    Cuellar Rodriguez, Immer Elias
    Levano Rodriguez, Danny
    [J]. ENFOQUE UTE, 2021, 12 (02): : 69 - 79
  • [32] Risk assesment methods - ISO/IEC 27001 information security managament system's key element
    Luczak, Jacek
    [J]. SCIENTIFIC JOURNALS OF THE MARITIME UNIVERSITY OF SZCZECIN-ZESZYTY NAUKOWE AKADEMII MORSKIEJ W SZCZECINIE, 2009, 19 (91): : 63 - 70
  • [33] Management of information security for an electric power utility -: On security domains and use of ISO/IEC17799 standard
    Ericsson, GN
    Torkilseng, Å
    [J]. IEEE TRANSACTIONS ON POWER DELIVERY, 2005, 20 (02) : 683 - 690
  • [34] PHYSICAL AND LOGICAL SECURITY MANAGEMENT ORGANIZATION MODEL BASED ON ISO 31000 AND ISO 27001
    Pecina, Koldo
    Estremera, Ricardo
    Bilbao, Alfonso
    Bilbao, Enrique
    [J]. 2011 IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2011,
  • [35] Research opportunities on manufacturing flexibility domain: A review and theory-based research agenda
    Perez-Perez, Marta
    Serrano Bedia, Ana-M.
    Lopez-Fernandez, Maria-Concepcion
    Garcia-Piqueres, Gema
    [J]. JOURNAL OF MANUFACTURING SYSTEMS, 2018, 48 : 9 - 20
  • [36] INTEGRATION OF THE GDPR REQUIREMENTS INTO THE REQUIREMENTS OF THE SR EN ISO/IEC 27001:2018 STANDARD, INTEGRATION SECURITY MANAGEMENT SYSTEM IN A SOFTWARE DEVELOPMENT COMPANY
    Gaspar, Mirabela Luciana
    Popescu, Sorin Gabriel
    [J]. ACTA TECHNICA NAPOCENSIS SERIES-APPLIED MATHEMATICS MECHANICS AND ENGINEERING, 2018, 61 (03): : 85 - 96
  • [37] Information security failures identified and measured - ISO/IEC 27001:2013 controls ranked based on GDPR penalty case analysis
    Suorsa, M.
    Helo, P.
    [J]. INFORMATION SECURITY JOURNAL, 2024, 33 (03): : 285 - 306
  • [38] On Developing Information Security Management System (ISMS) Framework for ISO 27001-based Data Center
    Achmadi, Dedy
    Suryanto, Yohan
    Ramli, Kalamullah
    [J]. 2018 INTERNATIONAL WORKSHOP ON BIG DATA AND INFORMATION SECURITY (IWBIS), 2018, : 149 - 157
  • [39] INTEGRATION POSSIBILITIES OF ISO 9001:2008 QUALITY MANAGEMENT SYSTEM WITH ISO 27001:2010 INFORMATION SECURITY MANAGEMENT SYSTEM
    Britvic, Josip
    Kovacevic, Anita Prelas
    Cingel, Monika
    [J]. 2. MEDUNARODNI ZNANSTVENI SIMPOZIJ GOSPODARSTVO ISTOCNE HRVATSKE - JUCER, DANAS, SUTRA, 2013, : 368 - 373
  • [40] Information security objectives and the output legitimacy of ISO/IEC 27001: stakeholders’ perspective on expectations in private organizations in Sweden
    Yasmin Kamil
    Sofia Lund
    M Sirajul Islam
    [J]. Information Systems and e-Business Management, 2023, 21 : 699 - 722