The ISO/IEC 27001 information security management standard: literature review and theory-based research agenda

被引:33
|
作者
Culot, Giovanna [1 ]
Nassimbeni, Guido [1 ]
Podrecca, Matteo [1 ]
Sartor, Marco [1 ]
机构
[1] Univ Udine, Polytech Dept Engn & Architecture, Udine, Italy
来源
TQM JOURNAL | 2021年 / 33卷 / 07期
关键词
ISO; IEC; 27001; Information security; Systematic literature review; Management system standards; SYSTEM STANDARDS; RISK-MANAGEMENT; CERTIFICATION; INTEGRATION; PERFORMANCE; FRAMEWORK; QUALITY; IMPACT; IMPLEMENTATION; ORGANIZATIONS;
D O I
10.1108/TQM-09-2020-0202
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
PurposeAfter 15 years of research, this paper aims to present a review of the academic literature on the ISO/IEC 27001, the most renowned standard for information security and the third most widespread ISO certification. Emerging issues are reframed through the lenses of social systems thinking, deriving a theory-based research agenda to inspire interdisciplinary studies in the field.Design/methodology/approachThe study is structured as a systematic literature review.FindingsResearch themes and sub-themes are identified on five broad research foci: relation with other standards, motivations, issues in the implementation, possible outcomes and contextual factors.Originality/valueThe study presents a structured overview of the academic body of knowledge on ISO/IEC 27001, providing solid foundations for future research on the topic. A set of research opportunities is outlined, with the aim to inspire future interdisciplinary studies at the crossroad between information security and quality management. Managers interested in the implementation of the standard and policymakers can find an overview of academic knowledge useful to inform their decisions related to implementation and regulatory activities.
引用
收藏
页码:76 / 105
页数:30
相关论文
共 50 条
  • [41] Model Driven Information Security Management - Evaluating and Applying the Meta Model of ISO 27001
    Milicevic, Danijel
    Goeken, Matthias
    [J]. AMCIS 2011 PROCEEDINGS, 2011,
  • [42] Information security objectives and the output legitimacy of ISO/IEC 27001: stakeholders' perspective on expectations in private organizations in Sweden
    Kamil, Yasmin
    Lund, Sofia
    Islam, M. Sirajul
    [J]. INFORMATION SYSTEMS AND E-BUSINESS MANAGEMENT, 2023, 21 (03) : 699 - 722
  • [43] Using the bell labs security framework to enhance the ISO 17799/27001 information security management system
    Mcgee, Andrew R.
    Bastry, Frank A.
    Chandrashekhar, Uma
    Vasireddy, S. Rao
    Flynn, Lori A.
    [J]. BELL LABS TECHNICAL JOURNAL, 2007, 12 (03) : 39 - 54
  • [44] Creating a Theory-Based Research Agenda for Gamification
    Putz, Lisa-Maria
    Treiblmaier, Horst
    [J]. AMCIS 2015 PROCEEDINGS, 2015,
  • [45] Information Security Management in High Quality IS Journals: A Review and Research Agenda
    Maynard, Sean B.
    Ahmad, Atif
    [J]. arXiv, 2022,
  • [46] A Theory-Based Review of Information Security Behavior in the Organization and Home Context
    Omidosu, Joseph
    Ophoff, Jacques
    [J]. 2016 THIRD INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATION AND ENGINEERING (ICACCE 2016), 2016, : 225 - 231
  • [47] Supporting the Development and Documentation of ISO 27001 Information Security Management Systems through Security Requirements Engineering Approaches
    Beckers, Kristian
    Fassbender, Stephan
    Heisel, Maritta
    Kuester, Jan-Christoph
    Schmidt, Holger
    [J]. ENGINEERING SECURE SOFTWARE AND SYSTEMS, 2012, 7159 : 14 - +
  • [48] Using Security Requirements Engineering Approaches to Support ISO 27001 Information Security Management Systems Development and Documentation
    Beckers, Kristian
    Fassbender, Stephan
    Heisel, Maritta
    Schmidt, Holger
    [J]. 2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 242 - 248
  • [49] Management theory and big data literature: From a review to a research agenda
    Fiorini, Paula de Camargo
    Roman Pais Seles, Bruno Michel
    Jabbour, Charbel Jose Chiappetta
    Mariano, Enzo Barberio
    Jabbour, Ana Beatriz Lopes de Sousa
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2018, 43 : 112 - 129
  • [50] Appraisal of Mask Manufacture Information Security Based on ISO27001 and Common Criteria
    Wang, Cynthia
    Guo, Eric
    Chen, Sammy
    Zhu, Sherry
    Wu, Jason
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEM), 2017, : 2317 - 2320