Information Security Failures Measured and ISO/IEC 27001:2022 Controls Ranked by General Data Protection Regulation Penalty Analysis
| annif.suggestions | data security|data protection|risk management|data systems|safety and security|enterprises|cyber security|root cause analysis|control systems|management (control)|en | en |
| annif.suggestions.links | http://www.yso.fi/onto/yso/p5479|http://www.yso.fi/onto/yso/p3636|http://www.yso.fi/onto/yso/p3134|http://www.yso.fi/onto/yso/p3927|http://www.yso.fi/onto/yso/p7349|http://www.yso.fi/onto/yso/p3128|http://www.yso.fi/onto/yso/p26189|http://www.yso.fi/onto/yso/p28670|http://www.yso.fi/onto/yso/p16975|http://www.yso.fi/onto/yso/p506 | en |
| dc.contributor.author | Suorsa, Mikko | |
| dc.contributor.author | Helo, Petri | |
| dc.contributor.faculty | fi=Tekniikan ja innovaatiojohtamisen yksikkö|en=School of Technology and Innovations| | - |
| dc.contributor.orcid | https://orcid.org/0000-0002-1649-4223 | - |
| dc.contributor.orcid | https://orcid.org/0000-0002-0501-2727 | - |
| dc.contributor.organization | fi=Vaasan yliopisto|en=University of Vaasa| | |
| dc.date.accessioned | 2024-03-21T07:51:36Z | |
| dc.date.accessioned | 2025-06-25T13:14:21Z | |
| dc.date.available | 2024-03-21T07:51:36Z | |
| dc.date.issued | 2023-11-30 | |
| dc.description.abstract | Selecting the most important information security controls is a critical and difficult process. Therefore, the decision-making on how to manage risks and threats has to be supported with data-driven performance measurement metrics. This paper identifies and explores the failures and impacts of information security, as well as the most effective controls to mitigate information security risks in organizations. The method of the study was root cause analysis. All year 2020 GDPR penalty cases (n=81) based on misconduct, as defined in GDPR Article 32: “Security of processing” were matched with ISO/IEC 27001:2022 controls, which were used as failure identifiers in the analysis. As a result, the study presents both, the top 10 most frequent and the top 10 most expensive information security failures corresponding to ISO/IEC 27001:2022 controls. Furthermore, the study also illustrates the correlation of these controls. | - |
| dc.description.notification | ©2023 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. | - |
| dc.description.reviewstatus | fi=vertaisarvioitu|en=peerReviewed| | - |
| dc.format.bitstream | true | |
| dc.format.content | fi=kokoteksti|en=fulltext| | - |
| dc.format.extent | 5 | - |
| dc.identifier.isbn | 979-8-3503-0596-8 | - |
| dc.identifier.olddbid | 20170 | |
| dc.identifier.oldhandle | 10024/17072 | |
| dc.identifier.uri | https://osuva.uwasa.fi/handle/11111/1761 | |
| dc.identifier.urn | URN:NBN:fi-fe2024032112241 | - |
| dc.language.iso | eng | - |
| dc.publisher | IEEE | - |
| dc.relation.conference | International Conference on Cyber and IT Service Management (CITSM) | - |
| dc.relation.doi | 10.1109/citsm60085.2023.10455413 | - |
| dc.relation.ispartof | 2023 11th International Conference on Cyber and IT Service Management (CITSM) | - |
| dc.relation.url | https://doi.org/10.1109/CITSM60085.2023.10455413 | - |
| dc.source.identifier | https://osuva.uwasa.fi/handle/10024/17072 | |
| dc.subject | Information security | - |
| dc.subject | IT risk management | - |
| dc.subject | IT compliance | - |
| dc.subject | ISO/IEC 27001:2022 | - |
| dc.subject | General Data Protection Regulation | - |
| dc.subject | GDPR | - |
| dc.subject.discipline | fi=Tuotantotalous|en=Industrial Management| | - |
| dc.title | Information Security Failures Measured and ISO/IEC 27001:2022 Controls Ranked by General Data Protection Regulation Penalty Analysis | - |
| dc.type.okm | fi=A4 Artikkeli konferenssijulkaisussa|en=A4 Peer-reviewed article in conference proceeding|sv=A4 Artikel i en konferenspublikation| | - |
| dc.type.publication | article | - |
| dc.type.version | acceptedVersion | - |
Tiedostot
1 - 1 / 1
Ladataan...
- Name:
- Osuva_Suorsa_Helo_2023.pdf
- Size:
- 287.24 KB
- Format:
- Adobe Portable Document Format
- Description:
- Article
