CYBER RISK MANAGEMENT AND ISO 27005 APPLIED IN ORGANIZATIONS: A SYSTEMATIC LITERATURE REVIEW

  • Cerqueira Junior A
  • Arima C
N/ACitations
Citations of this article
110Readers
Mendeley users who have this article in their library.

Abstract

With the advent of legislation and regulations in privacy and data protection, risk management provides information for organizations to plan actions and strategies in information security and cybersecurity. Thus, the use of international standards and references are utilized for the definition of programs and internal projects. This study aims to identify the motivations and goals for adoption of the ISO 27005 standard in organizations in productive systems. For the development of the research, a systematic literature review with the adoption of a protocol based on the PRISMA-P was conducted. The results achieved suggests that organizations seek to adopt ISO 27005 to attend functional and institutional motivations aiming to improve processes related to information security management, risk management, risk assessment, improve information security management and meet laws, regulations and stakeholders.

Cite

CITATION STYLE

APA

Cerqueira Junior, A. S., & Arima, C. H. (2023). CYBER RISK MANAGEMENT AND ISO 27005 APPLIED IN ORGANIZATIONS: A SYSTEMATIC LITERATURE REVIEW. REVISTA FOCO, 16(02), e1188. https://doi.org/10.54751/revistafoco.v16n2-215

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free