2013/03/03 by Mahsa Mohseni, Mohseni, Mahsa
Computer Science · #Computers and Society (cs.CY) #FOS: Computer and information sciences #Information and Cyber Security
paper · pdf · doi:10.48550/arxiv.1303.0468
openalex publication_date 2013/03/03 · openalex created_date 2016/06/24 · openalex updated_date 2026/07/28
The purpose of this study is proposing a model to determine the gaps between security standards requirements and the reality of implementation ISMS. The research approach analyzes the various industry standards relevant to information security and responses gained from interviewing with 45 individuals of IT professionals and information security experts (who are chosen with targeted sampling) in order to develop a model comprising factors and subfactors which assesses compliance with ISMS (Information Security Management System) in organizations. For hypothesis test, binomial test and for ranking of factors and sub factors, Friedman test was done. This model tested in a bank and the degree of compliance with ISMS calculated.