Exploring the Adoption of the International Information Security Management System Standard ISO/IEC 27001: A Web Mining-Based Analysis

被引:32
|
作者
Mirtsch, Mona [1 ,2 ]
Kinne, Jan [3 ,4 ,5 ]
Blind, Knut [6 ,7 ]
机构
[1] Bundesanstalt Mat Forsch & Prufung, Dept Accreditat & Conform Assessment, D-12489 Berlin, Germany
[2] Tech Univ Berlin, Innovat Econ, D-10587 Berlin, Germany
[3] ZEW Leibniz Ctr European Econ Res, D-68161 Mannheim, Germany
[4] Istari Ai UG Haftungsbeschrankt, D-68199 Mannheim, Germany
[5] Univ Salzburg, Dept Geoinformat Z GIS, A-5020 Salzburg, Austria
[6] Fraunhofer Inst Syst & Innovat Res, D-76139 Karlsruhe, Germany
[7] Tech Univ Berlin, Chair Innovat Econ, D-10587 Berlin, Germany
关键词
ISO Standards; IEC Standards; Information security; Standards organizations; Organizations; Environmental management; Adoption; information security; management system standards; standards; web mining; ISO-9000; CERTIFICATION; DIFFUSION; QUALITY; INNOVATION; TECHNOLOGY; DETERMINANTS; PERSPECTIVE; COMPETITION; STRATEGIES; ISO-14001;
D O I
10.1109/TEM.2020.2977815
中图分类号
F [经济];
学科分类号
02 ;
摘要
In the light of digitalization and recent EU policy initiatives, information is an important asset that organizations of all sizes and from all sectors should secure. However, in order to provide common requirements for the implementation of an information security management system, the internationally well-accepted ISO/IEC 27001 standard has not shown the expected growth rate since its publication more than a decade ago. In this article, we apply web mining to explore the adoption of ISO/IEC 27001 through a series of 2664 out of more than 900 000 German firms from the Mannheim Enterprise Panel dataset that refers to this standard on their websites. As a result, we present a ''landscape'' of ISO/IEC 27001 in Germany, which shows that firms not only seek certifications themselves but often refer on their websites to partners who are certified instead. Consequently, we estimate a probit model and find that larger and more innovative firms are more likely to be certified to ISO/IEC 27001 and that almost half of all certified firms belong to the information and communications technology (ICT) service sector. Based on our findings, we derive implications for policy makers and management and critically assess the suitability of web mining to explore the adoption of management system standards.
引用
收藏
页码:87 / 100
页数:14
相关论文
共 50 条
  • [1] AUTOMATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM BASED ON THE ISO/IEC 27001 STANDARD
    de la Rosa Martin, Tonyse
    [J]. REVISTA UNIVERSIDAD Y SOCIEDAD, 2021, 13 (05): : 495 - 506
  • [2] ADOPTION OF STANDARD FOR INFORMATION SECURITY ISO/IEC 27001 IN BOSNIA AND HERZEGOVINA
    Skopak, Anis
    Sakanovic, Semir
    [J]. INTERNATIONAL CONFERENCE ON ECONOMIC AND SOCIAL STUDIES (ICESOS'16): REGIONAL ECONOMIC DEVELOPMENT: ENTREPNEURSHIP AND INNOVATION, 2016, : 35 - 42
  • [3] ADOPTION OF THE INFORMATION SECURITY MANAGEMENT SYSTEM STANDARD ISO/IEC 27001: A STUDY AMONG GERMAN ORGANIZATIONS
    Mirtsch, Mona
    [J]. INTERNATIONAL JOURNAL FOR QUALITY RESEARCH, 2023, 17 (03) : 747 - 768
  • [4] NEW STANDARD ISO/IEC 27001:2013 OF INFORMATION SECURITY MANAGEMENT SYSTEM
    Drastich, Martin
    [J]. KNOWLEDGE FOR MARKET USE 2014: MEDIA AND COMMUNICATION IN THE 21ST CENTURY, 2014, : 387 - 393
  • [5] A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard
    Fonseca-Herrera, Omar A.
    Rojas, Alix E.
    Florez, Hector
    [J]. IAENG International Journal of Computer Science, 2021, 48 (02) : 1 - 10
  • [6] Information Security Risk Management: Handbook for ISO/IEC 27001
    Lomas, Elizabeth
    [J]. RECORDS MANAGEMENT JOURNAL, 2011, 21 (03) : 239 - +
  • [7] Information security fortification by ontological mapping of the ISO/IEC 27001 standard
    Fenz, Stefan
    Goluch, Gernot
    Ekelhart, Andreas
    Riedl, Bernhard
    Weippl, Edgar
    [J]. 13TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2007, : 381 - +
  • [8] Information Security Management Systems - A Maturity Model Based on ISO/IEC 27001
    Proenca, Diogo
    Borbinha, Jose
    [J]. BUSINESS INFORMATION SYSTEMS (BIS 2018), 2018, 320 : 102 - 114
  • [9] COMPARATIVE STUDY REGARDING INTERNATIONAL STANDARDS ON INFORMATION SECURITY MANAGEMENT SYSTEMS IN ORGANIZATIONS: ISO/IEC 27001:2013 vs ISO/IEC 27001:2005
    Tiganoaia, Bogdan
    [J]. GLOBALIZATION AND INTERCULTURAL DIALOGUE: MULTIDISCIPLINARY PERSPECTIVES - ECONOMY AND MANAGEMENT, 2014, : 102 - 109
  • [10] The ISO/IEC 27001 information security management standard: literature review and theory-based research agenda
    Culot, Giovanna
    Nassimbeni, Guido
    Podrecca, Matteo
    Sartor, Marco
    [J]. TQM JOURNAL, 2021, 33 (07): : 76 - 105