Skip to main content
QUICK REVIEW

[Paper Review] An Adaptable Maturity Strategy for Information Security

Gliner Dias Alencar, Hermano Perrelli de Moura|arXiv (Cornell University)|Jul 17, 2018
Information and Cyber Security15 references4 citations
TL;DR

This paper proposes an adaptable maturity strategy for information security that classifies ISO/IEC 27001 and 27002 controls into four priority stages based on input from 157 organizations. By integrating COBIT maturity levels and a risk analysis matrix, the strategy enables tailored implementation and prioritization of security actions, validated successfully in a real-world company setting.

ABSTRACT

The lack of security in information systems has caused numerous financial and moral losses to several organizations. The organizations have a series of information security measures recommended by literature and international standards. However, the implementation of policies, actions, and adjustment to such standards is not simple and must be addressed by specific needs identified by the Information Security Governance in each organization. There are many challenges in effectively establishing, maintaining, and measuring information security in a way that adds value. Those challenges demonstrate a need for further investigations which address the problem. This paper presents a strategy to measure the maturity in information security aiming, also, to assist in the application and prioritization of information security actions in the corporate environment. For this, a survey was used as the main methodological instrument, reaching 157 distinct companies. As a result, it was possible to classify the ISO/IEC 27001 and 27002 controls in four stages according to the importance given by the companies. The COBIT maturity levels and a risk analysis matrix were also used. Finally, the adaptable strategy was successfully tested in a company

Motivation & Objective

  • To address the challenge of effectively measuring, implementing, and prioritizing information security controls across diverse organizations.
  • To identify the relative importance of ISO/IEC 27001 and 27002 controls based on real-world organizational input.
  • To develop a flexible maturity strategy that supports tailored security implementation aligned with organizational needs and risk profiles.
  • To validate the strategy through practical application in a corporate environment.

Proposed method

  • A survey was conducted across 157 companies to assess the perceived importance of individual ISO/IEC 27001 and 27002 controls.
  • Controls were classified into four maturity stages based on the survey results, reflecting organizational priorities.
  • COBIT maturity levels were used to assess the current state of information security processes within organizations.
  • A risk analysis matrix was applied to evaluate the potential impact and likelihood of control failures.
  • The integrated framework combines survey-based prioritization, COBIT maturity assessment, and risk analysis to guide action planning.
  • The strategy was tested in a real company to evaluate its practical applicability and effectiveness.

Experimental results

Research questions

  • RQ1How do organizations prioritize information security controls from ISO/IEC 27001 and 27002 in practice?
  • RQ2What factors influence the perceived importance of specific security controls across different organizations?
  • RQ3How can COBIT maturity levels and risk analysis be combined to guide security control prioritization?
  • RQ4To what extent can a maturity strategy be adapted to fit the unique needs of individual organizations?
  • RQ5How effective is the proposed strategy in guiding the implementation of security actions in a real corporate environment?

Key findings

  • The survey revealed significant variation in how organizations prioritize ISO/IEC 27001 and 27002 controls, indicating no one-size-fits-all approach.
  • Controls were successfully grouped into four maturity stages based on organizational input, reflecting differing priorities across sectors and company sizes.
  • The integration of COBIT maturity levels and risk analysis provided a structured method for assessing and guiding security improvement efforts.
  • The adaptable strategy enabled targeted implementation of security actions, improving alignment with organizational risk profiles and governance needs.
  • The strategy was successfully validated in a real company, demonstrating its practical feasibility and value in guiding security maturity progression.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.