Mapping and Integrating Security and Risk Standards: a Systematic Literature Review

被引:0
|
作者
Fernandes, Andre [1 ]
Cruz, Joao [1 ]
da Silva, Miguel Mira [1 ]
Pereira, Ruben [2 ]
机构
[1] Univ Lisbon, INOV INESC INOVACAO, Lisbon, Portugal
[2] Univ Inst Lisbon, ISCTE, Lisbon, Portugal
关键词
Mapping; Integration; Harmonization; Systematic Literature Review; Standards; Risk; Security; Business Continuity; MANAGEMENT; FRAMEWORK; ONTOLOGY; COBIT;
D O I
10.3897/jucs.111677
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Organizations are under increasing pressure to comply with various rules, standards, and policies in today's regulatory environment. Compliance controls are put in place to avoid legal or regulatory violations, which could lead to severe penalties, loss of reputation, and financial damages. However, these controls may have similar scopes and objectives, resulting in duplicated work and unnecessary costs for the organizations. To address this issue, researchers carry out the mapping and integration of these standards to avoid duplication, streamline compliance efforts, and identify best practices. Our work aims to improve the State -of -the -Art by exploring the main benefits and problems resulting from these processes, as well as identifying methods or artifacts that can be reused in the future. We focus on the fields of Risk, Security, and Business Continuity, as these are critical areas where compliance is crucial for organizations. Through our research, we have found that current methods of generating mapping artifacts are not only cumbersome to execute but also ineffective, as they output a single artifact without the reasoning behind it.
引用
收藏
页码:433 / 448
页数:16
相关论文
共 50 条
  • [31] HTTPS Contribution in Web Application Security: A Systematic Literature Review
    Wijitrisnanto, Fajar
    Suhardi
    Yustianto, Purnomo
    2020 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY SYSTEMS AND INNOVATION (ICITSI), 2020, : 347 - 356
  • [32] Software Risk Prediction: Systematic Literature Review on Machine Learning Techniques
    Mahmud, Mahmudul Hoque
    Nayan, Md Tanzirul Haque
    Ashir, Dewan Md Nur Anjum
    Kabir, Md Alamgir
    APPLIED SCIENCES-BASEL, 2022, 12 (22):
  • [33] Applying Value Stream Mapping in Manufacturing: A Systematic Literature Review
    Romero, L. F.
    Arce, A.
    IFAC PAPERSONLINE, 2017, 50 (01): : 1075 - 1086
  • [34] Mapping digital innovation: A bibliometric analysis and systematic literature review
    Cheng, Cong
    Wang, Limin
    Xie, Hongming
    Yan, Lulu
    TECHNOLOGICAL FORECASTING AND SOCIAL CHANGE, 2023, 194
  • [35] Integrating artificial intelligence and analytics in smart grids: a systematic literature review
    Khosrojerdi, Farhad
    Akhigbe, Okhaide
    Gagnon, Stephane
    Ramirez, Alex
    Richards, Gregory
    INTERNATIONAL JOURNAL OF ENERGY SECTOR MANAGEMENT, 2022, 16 (02) : 318 - 338
  • [36] A Systematic Literature Review of Information Security in Chatbots
    Yang, Jing
    Chen, Yen-Lin
    Por, Lip Yee
    Ku, Chin Soon
    APPLIED SCIENCES-BASEL, 2023, 13 (11):
  • [37] Food security governance: a systematic literature review
    Jeroen J. L. Candel
    Food Security, 2014, 6 : 585 - 601
  • [38] BYOD security issues: a systematic literature review
    Ratchford, Melva
    El-Gayar, Omar
    Noteboom, Cherie
    Wang, Yong
    INFORMATION SECURITY JOURNAL, 2022, 31 (03): : 253 - 273
  • [39] System security assurance: A systematic literature review
    Shukla, Ankur
    Katt, Basel
    Nweke, Livinus Obiora
    Yeng, Prosper Kandabongee
    Weldehawaryat, Goitom Kahsay
    COMPUTER SCIENCE REVIEW, 2022, 45
  • [40] Food security governance: a systematic literature review
    Candel, Jeroen J. L.
    FOOD SECURITY, 2014, 6 (04) : 585 - 601