ISO/IEC 27001 Implementation in Public Organizations: A Case Study

被引:0
|
作者
Sussy, Bayona [1 ]
Wilber, Chauca [1 ]
Milagros, Lopez [1 ]
Carlos, Maldonado [1 ]
机构
[1] Univ Nacl Mayor San Marcos, Unidad Posgrado, Fac Ingn Sistemas & Informat, Av German Amezaga 375, Lima, Peru
关键词
critical success factors; NTP ISO/IEC 27001; information security management system; ISMS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, due to the intensive use of information technology, the information security has become a crucial and strategic issue in organizational management. Various standards and guidelines for security information as ISO/IEC 27001, ISO/IEC 27002, and COBIT have been developed; however, organizations still face difficulties in their implementation. This paper presents the current situation of the ISO/IEC 27001 implementation process in Peruvian public organizations. As a result of literature review, the critical success factors for successful implementation of ISO/IEC 7001 were identified. Furthermore, it was conducted a review of the ISO/IEC 27001 implementation in five organizations, taking into consideration the critical success factors identified. From the results obtained, it is concluded that there is the need for considering not only technical, legal, and organizational issues but also factors related to people such as training, knowledge and awareness raising in order to get success of information security management.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] POSSIBILITIES OF ISO 9001: 2015 QMS AND ISO/IEC 27001:2013 ISMS INTEGRATION
    Britvic, Josip
    Merkas, Zvonko
    Tenjeri, Tihomir
    INTERDISCIPLINARY MANAGEMENT RESEARCH XVII (IMR 2021), 2021, : 585 - 600
  • [22] INTEGRATING THE INFORMATION SECURITY MANAGEMENT SYSTEM (ISO/IEC 27001) WITH OTHER MANAGEMENT SYSTEMS: A CASE STUDY IN A PHARMACEUTICAL ORGANISATION
    Oliveira, Rui
    Silva, Rui
    Rebelo, Manuel Ferreira
    IRF2016: 5TH INTERNATIONAL CONFERENCE INTEGRITY-RELIABILITY-FAILURE, 2016, : 843 - 844
  • [23] Information security and value creation: The performance implications of ISO/IEC 27001
    Podrecca, Matteo
    Culot, Giovanna
    Nassimbeni, Guido
    Sartor, Marco
    COMPUTERS IN INDUSTRY, 2022, 142
  • [24] Elements for the implementation of ISO/IEC 17025 in Angolan public laboratories
    Gaspar, Marcia
    Ramirez-Valdivia, Martha
    2021 IEEE IFAC INTERNATIONAL CONFERENCE ON AUTOMATION/XXIV CONGRESS OF THE CHILEAN ASSOCIATION OF AUTOMATIC CONTROL (IEEE IFAC ICA - ACCA2021), 2021,
  • [25] Information security fortification by ontological mapping of the ISO/IEC 27001 standard
    Fenz, Stefan
    Goluch, Gernot
    Ekelhart, Andreas
    Riedl, Bernhard
    Weippl, Edgar
    13TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2007, : 381 - +
  • [26] ADOPTION OF STANDARD FOR INFORMATION SECURITY ISO/IEC 27001 IN BOSNIA AND HERZEGOVINA
    Skopak, Anis
    Sakanovic, Semir
    INTERNATIONAL CONFERENCE ON ECONOMIC AND SOCIAL STUDIES (ICESOS'16): REGIONAL ECONOMIC DEVELOPMENT: ENTREPNEURSHIP AND INNOVATION, 2016, : 35 - 42
  • [27] Compliance with Saudi NCA-ECC based on ISO/IEC 27001
    Alsahafi, Tahani
    Halboob, Waleed
    Almuhtadi, Jalal
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2022, 29 (06): : 2090 - 2097
  • [28] A GAP ANALYSIS TOOL FOR SMES TARGETING ISO/IEC 27001 COMPLIANCE
    Valdevit, Thierry
    Mayer, Nicolas
    ICEIS 2010: PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL 3: INFORMATION SYSTEMS ANALYSIS AND SPECIFICATION, 2010, : 413 - 416
  • [29] A View on ISO/IEC 27001 Compliant Identity Lifecycles for IT Service Providers
    Kurowski, Sebastian
    Litwing, Richard
    Lueckemeyer, Gero
    2015 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2015, : 85 - 90
  • [30] Information security and value creation: The performance implications of ISO/IEC 27001
    Podrecca, Matteo
    Culot, Giovanna
    Nassimbeni, Guido
    Sartor, Marco
    Computers in Industry, 2022, 142