Mapping and Integrating Security and Risk Standards: a Systematic Literature Review

被引:0
|
作者
Fernandes, Andre [1 ]
Cruz, Joao [1 ]
da Silva, Miguel Mira [1 ]
Pereira, Ruben [2 ]
机构
[1] Univ Lisbon, INOV INESC INOVACAO, Lisbon, Portugal
[2] Univ Inst Lisbon, ISCTE, Lisbon, Portugal
关键词
Mapping; Integration; Harmonization; Systematic Literature Review; Standards; Risk; Security; Business Continuity; MANAGEMENT; FRAMEWORK; ONTOLOGY; COBIT;
D O I
10.3897/jucs.111677
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Organizations are under increasing pressure to comply with various rules, standards, and policies in today's regulatory environment. Compliance controls are put in place to avoid legal or regulatory violations, which could lead to severe penalties, loss of reputation, and financial damages. However, these controls may have similar scopes and objectives, resulting in duplicated work and unnecessary costs for the organizations. To address this issue, researchers carry out the mapping and integration of these standards to avoid duplication, streamline compliance efforts, and identify best practices. Our work aims to improve the State -of -the -Art by exploring the main benefits and problems resulting from these processes, as well as identifying methods or artifacts that can be reused in the future. We focus on the fields of Risk, Security, and Business Continuity, as these are critical areas where compliance is crucial for organizations. Through our research, we have found that current methods of generating mapping artifacts are not only cumbersome to execute but also ineffective, as they output a single artifact without the reasoning behind it.
引用
收藏
页码:433 / 448
页数:16
相关论文
共 50 条
  • [21] A Systematic Literature Review of Organization Resilience, Business Continuity, and Risk: Towards Process Resilience and Continuity
    Ostadi, Bakhtiar
    Ebrahimi-Sadrabadi, Mahnaz
    Sepehri, Mohammad Mehdi
    Kashan, Ali Husseinzadeh
    IRANIAN JOURNAL OF MANAGEMENT STUDIES, 2023, 16 (01) : 229 - 257
  • [22] Security testing of web applications: A systematic mapping of the literature
    Aydos, Murat
    Aldan, Cigdem
    Coskun, Evren
    Soydan, Alperen
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (09) : 6775 - 6792
  • [23] Collaborative risk management: a systematic literature review
    Friday, Derek
    Ryan, Suzanne
    Sridharan, Ramaswami
    Collins, David
    INTERNATIONAL JOURNAL OF PHYSICAL DISTRIBUTION & LOGISTICS MANAGEMENT, 2018, 48 (03) : 231 - 253
  • [24] Systematic literature review on the security challenges of blockchain in IoT-based smart cities
    Yu, Zhihao
    Song, Liang
    Jiang, Linhua
    Sharafi, Omid Khold
    KYBERNETES, 2022, 51 (01) : 323 - 347
  • [25] Security attacks in Opportunistic Mobile Networks: A systematic literature review
    Altaweel, Ala
    Aslam, Sidra
    Kamel, Ibrahim
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 221
  • [26] Benefits and Challenges in Information Security Certification - A Systematic Literature Review
    Hulshof, Mike
    Daneva, Maya
    BUSINESS MODELING AND SOFTWARE DESIGN (BMSD 2021), 2021, 422 : 154 - 169
  • [27] Artificial intelligence for system security assurance: A systematic literature review
    Wen, Shao-Fang
    Shukla, Ankur
    Katt, Basel
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2025, 24 (01)
  • [28] Diversification and obfuscation techniques for software security: A systematic literature review
    Hosseinzadeh, Shohreh
    Rauti, Sampsa
    Lauren, Samuel
    Makela, Jari-Matti
    Holvitie, Johannes
    Hyrynsalmi, Sami
    Leppanen, Ville
    INFORMATION AND SOFTWARE TECHNOLOGY, 2018, 104 : 72 - 93
  • [29] Web Services Attacks and Security- A Systematic Literature Review
    Mouli, Varsha R.
    Jevitha, K. P.
    PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING AND COMMUNICATIONS, 2016, 93 : 870 - 877
  • [30] Standards, Processes, and Tools Used to Evaluate the Quality of Health Information Systems: Systematic Literature Review
    Noel, Rene
    Taramasco, Carla
    Marquez, Gaston
    JOURNAL OF MEDICAL INTERNET RESEARCH, 2022, 24 (03)