Benefits and Challenges in Information Security Certification - A Systematic Literature Review

被引:5
作者
Hulshof, Mike [1 ]
Daneva, Maya [1 ]
机构
[1] Univ Twente, NL-7522 NH Enschede, Netherlands
来源
BUSINESS MODELING AND SOFTWARE DESIGN (BMSD 2021) | 2021年 / 422卷
关键词
Security accreditation; Security certification; Information security auditing practice; Systematic literature review; AUDIT; MANAGEMENT;
D O I
10.1007/978-3-030-79976-2_9
中图分类号
F [经济];
学科分类号
02 ;
摘要
Information security certification (ISC) gets increasingly more complex. Although certain benefits, challenges and success factors have been recognized by both scholars and practitioners in the field, little has been done to consolidate the published knowledge. This systematic literature review attempts to consolidate what is currently known on the benefits of ISC, the issues and the challenges to certification, and the success factors that organizations consider while embarking on this process. Following the guidelines of Kitchenham et al., and Kuhrmann et al., we examined 42 papers that are relevant to our area of interest. We identified 12 benefits, 15 challenges, and 8 success factors. Our most important conclusion is that the current certification process is complex and suboptimal; it is expensive and it depends on the auditor's skills. Finally, we evaluated validity threats and derived some implications for practice and for research.
引用
收藏
页码:154 / 169
页数:16
相关论文
共 44 条
  • [1] Aditya B.R., 2018, ICST, V1
  • [2] Aditya B. R., 2018, IOP Conference Series: Materials Science and Engineering, V407
  • [3] Ali Saqib, 2015, Journal of Theoretical and Applied Information Technology, V79, P514
  • [4] [Anonymous], 2009, CREAT INNOV MANAG
  • [5] [Anonymous], 2012, LNCS, DOI DOI 10.1007/978-3-642-30241-1_10
  • [6] Ariffin I, 2014, 2014 INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION SCIENCES (ICCOINS)
  • [7] Explaining the information systems auditor role in the public sector financial audit
    Axelsen, Micheal
    Green, Peter
    Ridley, Gail
    [J]. INTERNATIONAL JOURNAL OF ACCOUNTING INFORMATION SYSTEMS, 2017, 24 : 15 - 31
  • [8] Brand D, 2016, EDPACS, V54
  • [9] Brosgol B.M., 2008, CROSSTALK J DEFENSE, V21, P9
  • [10] The information audit: Theory versus practice
    Buchanan, Steven
    Gibb, Forbes
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2008, 28 (03) : 150 - 160