Home // International Journal On Advances in Software, volume 12, numbers 3 and 4, 2019 // View article


Approaches to Develop and Implement ISO/IEC 27001 Standard - Information Security Management Systems: A Systematic Literature Review

Authors:
Daniel Ganji
Christos Kalloniatis
Haralambos Mouratidis
Saeed Malekshahi Gheytassi

Keywords: ISO/IEC 27001; information security management systems; PDCA; requirements engineering; information security risk management

Abstract:
This systematic literature review intends to determine the extent to which contribution is available to assist organisations and interested parties to understand better or comply with the requirements of the ISO/IEC 27001 international standard, known as Information Security Management Systems (ISMS). The primary aim of this paper is to explore the current literature in the ISMS as specified by the ISO/IEC 27001 standard, aiming to provide a mapping of their contributions with the requirements of the standard. An objective of this study is to explore the ways in which the literature addresses the requirements of the ISMS. This study uses semi-quantitative analysis in order to gain insights into the concepts and techniques around the ISMS and to systematically obtain data to help with identifying the research gaps. One of the findings of this review is to encourage to benefit from available literature and to develop an ISMS to promote their corporate compliance with a well-established standard. The most striking result from the review is that the majority of approaches proposed by scholars between 2005 to 2018 are with limited support in adopting the information security management system. Another important finding is that almost all available approaches fundamentally lack the motivation to focus on the analysis and application of the ISMS with no single study enable organisations to adopt the ISO/IEC 27001 standard.

Pages: 228 to 238

Copyright: Copyright (c) to authors, 2019. Used with permission.

Publication date: December 30, 2019

Published in: journal

ISSN: 1942-2628