Mapping and Integrating Security and Risk Standards: a Systematic Literature Review

被引:0
|
作者
Fernandes, Andre [1 ]
Cruz, Joao [1 ]
da Silva, Miguel Mira [1 ]
Pereira, Ruben [2 ]
机构
[1] Univ Lisbon, INOV INESC INOVACAO, Lisbon, Portugal
[2] Univ Inst Lisbon, ISCTE, Lisbon, Portugal
关键词
Mapping; Integration; Harmonization; Systematic Literature Review; Standards; Risk; Security; Business Continuity; MANAGEMENT; FRAMEWORK; ONTOLOGY; COBIT;
D O I
10.3897/jucs.111677
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Organizations are under increasing pressure to comply with various rules, standards, and policies in today's regulatory environment. Compliance controls are put in place to avoid legal or regulatory violations, which could lead to severe penalties, loss of reputation, and financial damages. However, these controls may have similar scopes and objectives, resulting in duplicated work and unnecessary costs for the organizations. To address this issue, researchers carry out the mapping and integration of these standards to avoid duplication, streamline compliance efforts, and identify best practices. Our work aims to improve the State -of -the -Art by exploring the main benefits and problems resulting from these processes, as well as identifying methods or artifacts that can be reused in the future. We focus on the fields of Risk, Security, and Business Continuity, as these are critical areas where compliance is crucial for organizations. Through our research, we have found that current methods of generating mapping artifacts are not only cumbersome to execute but also ineffective, as they output a single artifact without the reasoning behind it.
引用
收藏
页码:433 / 448
页数:16
相关论文
共 50 条
  • [41] A Systematic Literature Review: Information Security Culture
    Mahfuth, Amjad
    Yussof, Salman
    Abu Baker, Asmidar
    Ali, Nor'ashikin
    2017 5TH INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS (ICRIIS 2017): SOCIAL TRANSFORMATION THROUGH DATA SCIENCE, 2017,
  • [42] Leveraging Blockchain Technology for Ensuring Security and Privacy Aspects in Internet of Things: A Systematic Literature Review
    Zubaydi, Haider Dhia
    Varga, Pal
    Molnar, Sandor
    SENSORS, 2023, 23 (02)
  • [43] Exploring the Influence of Direct and Indirect Factors on Information Security Policy Compliance: A Systematic Literature Review
    Alassaf, Mada
    Alkhalifah, Ali
    IEEE ACCESS, 2021, 9 : 162687 - 162705
  • [44] A systematic literature review of communications standards in discrete manufacturing
    Ercan, Furkan
    Bega, Maximilian
    Kuhlenkoetter, Bernd
    PROCEEDINGS OF THE CONFERENCE ON PRODUCTION SYSTEMS AND LOGISTICS, CPSL 2023-2, 2023, : 80 - 89
  • [45] A systematic literature review of the role of trust and security on Fintech adoption in banking
    Jafri, Johan Ariff
    Amin, Syajarul Imna Mohd
    Rahman, Aisyah Abdul
    Nor, Shifa Mohd
    HELIYON, 2024, 10 (01)
  • [46] Security as an emerging dimension of Digital Literacy for education: a systematic literature review
    Rocha Estrada, Francisco Javier
    Enrique George-Reyes, Carlos
    David Glasserman-Morales, Leonardo
    JOURNAL OF E-LEARNING AND KNOWLEDGE SOCIETY, 2022, 18 (02): : 22 - 33
  • [47] Cyber Risk in Health Facilities: A Systematic Literature Review
    Sardi, Alberto
    Rizzi, Alessandro
    Sorano, Enrico
    Guerrieri, Anna
    SUSTAINABILITY, 2020, 12 (17)
  • [48] Systematic Literature Review (SLR) of Resource Scheduling and Security in Cloud Computing
    Sheikh, Abdullah
    Munro, Malcolm
    Budgen, David
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (04) : 35 - 44
  • [49] Information Security Risk Management in IT Outsourcing - A Quarter-century Systematic Literature Review
    Bhatti, Baber Majid
    Mubarak, Sameera
    Nagalingam, Sev
    JOURNAL OF GLOBAL INFORMATION TECHNOLOGY MANAGEMENT, 2021, 24 (04) : 259 - 298
  • [50] Improving Security Architecture of Internet of Medical Things: A Systematic Literature Review
    Mahmood, Mudasir
    Khan, Muhammad Ijaz
    Ziauddin
    Hussain, Hameed
    Khan, Inayat
    Rahman, Shahid
    Shabir, Muhammad
    Niazi, Badam
    IEEE ACCESS, 2023, 11 : 107725 - 107753