2019
DOI: 10.4301/s1807-1775201916007
|View full text |Cite
|
Sign up to set email alerts
|

Multicriteria analysis of the compliance for the improvement of information security

Abstract: Information security is a current issue of protection of information assets that considers significant variables of a strategic, organizational and IT governance nature, and that requires to analyze the compliance with international standards that regulate business actions. In this way, the work analyzes institutional compliance to improve information security applying the Analytic Hierarchy Process methodology to the specific practices defined in ISO/IEC 27002:2013. Expert Choice has been used as Decision Sup… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
4
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
3

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(4 citation statements)
references
References 41 publications
0
4
0
Order By: Relevance
“…A generalized comparison of the methods is given in Table 4. It is worth noting that the AHP method is very often used in scientific articles in the engineering field [34]. This method uses the hierarchical structure of the problem, breaking the problem into smaller parts and, consequently, evaluating all aspects of the problem [35].…”
Section: Comparison Of Mcdm Methodsmentioning
confidence: 99%
“…A generalized comparison of the methods is given in Table 4. It is worth noting that the AHP method is very often used in scientific articles in the engineering field [34]. This method uses the hierarchical structure of the problem, breaking the problem into smaller parts and, consequently, evaluating all aspects of the problem [35].…”
Section: Comparison Of Mcdm Methodsmentioning
confidence: 99%
“…b-Information Security Management System (ISMS) An Information Security Management System (ISMS) is a set of policies, procedures, and guidelines that help organizations manage their information security risks, protect their critical data, and ensure the confidentiality, integrity, and availability of their information (Solana-González, 2019). ISMS is based on the principle of continuous improvement, which means that organizations must regularly review and update their information security policies and procedures to adapt to changes in the threat landscape and ensure that they remain effective (Solana-González, 2019;Al-Dhahri, 2017). The implementation of an ISMS is not only important for protecting an organization's information assets but is also a requirement for compliance with various industry standards and regulations.…”
Section: -Backgroundmentioning
confidence: 99%
“…Examples of such standards include ISO 27001, which is an international standard for information security management, and the Payment Card Industry Data Security Standard (PCI DSS), which is a set of requirements for organizations that handle payment card data (Berisha-Shaqiri, 2014). Overall, an ISMS is a critical component of a strong cybersecurity posture, helping organizations manage risks and protect their operations and reputation (Pedro, 2019). c. Cyber Security Standards Cybersecurity standards are sets of guidelines, procedures, and practices that help organizations to protect their computer systems, networks, and data from unauthorized access, theft, damage, or other cyber threats.…”
Section: -Backgroundmentioning
confidence: 99%
“…Guo et al discuss privacy in the context of self-governance and social networks [47]. From the perspective of ISO/IEC 27002:2013, Solana-González et al found that practices related to privacy and protection of personal identifiable information play the least role in the decision-making process related to improvements in information security requirements in organizations [48]. The scarcity of work on privacy and IT governance and evidence such as that found in Solana-González et al's research signals for future studies.…”
Section: Further Workmentioning
confidence: 99%