{"id":"https://openalex.org/W2943913887","doi":"https://doi.org/10.1109/is.2018.8710558","title":"On the Track of ISO/IEC 27001:2013 Implementation Difficulties in Portuguese Organizations","display_name":"On the Track of ISO/IEC 27001:2013 Implementation Difficulties in Portuguese Organizations","publication_year":2018,"publication_date":"2018-09-01","ids":{"openalex":"https://openalex.org/W2943913887","doi":"https://doi.org/10.1109/is.2018.8710558","mag":"2943913887"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/is.2018.8710558","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5030473078","display_name":"Ana Longras","orcid":"https://orcid.org/0000-0002-8732-6892"},"institutions":[{"id":"https://openalex.org/I192341844","display_name":"Polytechnic Institute of Viana do Castelo","ror":"https://ror.org/03w6kry90","country_code":"PT","type":"education","lineage":["https://openalex.org/I192341844"]}],"countries":["PT"],"is_corresponding":false,"raw_author_name":"Ana Longras","raw_affiliation_strings":["Institute Polit\u00e9cnico de Viana do Castelo, Viana do Castelo, Portugal"],"affiliations":[{"raw_affiliation_string":"Institute Polit\u00e9cnico de Viana do Castelo, Viana do Castelo, Portugal","institution_ids":["https://openalex.org/I192341844"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047438044","display_name":"Teresa Pereira","orcid":"https://orcid.org/0000-0002-5845-4086"},"institutions":[{"id":"https://openalex.org/I192341844","display_name":"Polytechnic Institute of Viana do Castelo","ror":"https://ror.org/03w6kry90","country_code":"PT","type":"education","lineage":["https://openalex.org/I192341844"]},{"id":"https://openalex.org/I99682543","display_name":"University of Minho","ror":"https://ror.org/037wpkx04","country_code":"PT","type":"education","lineage":["https://openalex.org/I99682543"]}],"countries":["PT"],"is_corresponding":false,"raw_author_name":"Teresa Pereira","raw_affiliation_strings":["ARC4DigiT, Institute Polit\u00e9cnico de Viana do Castelo and Centro Algoritmi, Universidade do Minho, Braga, Portugal"],"affiliations":[{"raw_affiliation_string":"ARC4DigiT, Institute Polit\u00e9cnico de Viana do Castelo and Centro Algoritmi, Universidade do Minho, Braga, Portugal","institution_ids":["https://openalex.org/I192341844","https://openalex.org/I99682543"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020128995","display_name":"Pedro Carneiro","orcid":"https://orcid.org/0000-0003-1557-4181"},"institutions":[{"id":"https://openalex.org/I192341844","display_name":"Polytechnic Institute of Viana do Castelo","ror":"https://ror.org/03w6kry90","country_code":"PT","type":"education","lineage":["https://openalex.org/I192341844"]},{"id":"https://openalex.org/I201025148","display_name":"Universidade Aberta","ror":"https://ror.org/02rv3w387","country_code":"PT","type":"education","lineage":["https://openalex.org/I201025148"]}],"countries":["PT"],"is_corresponding":false,"raw_author_name":"Pedro Carneiro","raw_affiliation_strings":["ARC4DigiT, Institute Polit\u00e9cnico de Viana do Castelo and LE@D, Universidade Aberta, Lisboa, Portugal"],"affiliations":[{"raw_affiliation_string":"ARC4DigiT, Institute Polit\u00e9cnico de Viana do Castelo and LE@D, Universidade Aberta, Lisboa, Portugal","institution_ids":["https://openalex.org/I192341844","https://openalex.org/I201025148"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5083326114","display_name":"Pedro Pinto","orcid":"https://orcid.org/0000-0003-1856-6101"},"institutions":[{"id":"https://openalex.org/I192341844","display_name":"Polytechnic Institute of Viana do Castelo","ror":"https://ror.org/03w6kry90","country_code":"PT","type":"education","lineage":["https://openalex.org/I192341844"]},{"id":"https://openalex.org/I4210166615","display_name":"INESC TEC","ror":"https://ror.org/05fa8ka61","country_code":"PT","type":"nonprofit","lineage":["https://openalex.org/I4210125590","https://openalex.org/I4210166615"]}],"countries":["PT"],"is_corresponding":false,"raw_author_name":"Pedro Pinto","raw_affiliation_strings":["ARC4DigiT, Institute Polit\u00e9cnico de Viana do Castelo and INESCTEC, Porto, Portugal"],"affiliations":[{"raw_affiliation_string":"ARC4DigiT, Institute Polit\u00e9cnico de Viana do Castelo and INESCTEC, Porto, Portugal","institution_ids":["https://openalex.org/I192341844","https://openalex.org/I4210166615"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.876,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.605926,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":85,"max":86},"biblio":{"volume":null,"issue":null,"first_page":"886","last_page":"890"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10761","display_name":"Vehicular Ad Hoc Networks (VANETs)","score":0.9696,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10761","display_name":"Vehicular Ad Hoc Networks (VANETs)","score":0.9696,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9588,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.9182,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/itil-security-management","display_name":"ITIL security management","score":0.71758586},{"id":"https://openalex.org/keywords/information-security-management","display_name":"Information security management","score":0.49886322},{"id":"https://openalex.org/keywords/information-security-standards","display_name":"Information security standards","score":0.4228707}],"concepts":[{"id":"https://openalex.org/C111153917","wikidata":"https://www.wikidata.org/wiki/Q1662500","display_name":"Information security management system","level":5,"score":0.8710723},{"id":"https://openalex.org/C114351632","wikidata":"https://www.wikidata.org/wiki/Q5974820","display_name":"ITIL security management","level":5,"score":0.71758586},{"id":"https://openalex.org/C46304622","wikidata":"https://www.wikidata.org/wiki/Q374814","display_name":"Certification","level":2,"score":0.651651},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.61385816},{"id":"https://openalex.org/C169537543","wikidata":"https://www.wikidata.org/wiki/Q1056312","display_name":"Certified Information Systems Security Professional","level":5,"score":0.58846724},{"id":"https://openalex.org/C47309137","wikidata":"https://www.wikidata.org/wiki/Q7598357","display_name":"Standard of Good Practice","level":5,"score":0.5377121},{"id":"https://openalex.org/C148976360","wikidata":"https://www.wikidata.org/wiki/Q1662500","display_name":"Information security management","level":5,"score":0.49886322},{"id":"https://openalex.org/C2776748549","wikidata":"https://www.wikidata.org/wiki/Q201610","display_name":"Status quo","level":2,"score":0.49810767},{"id":"https://openalex.org/C180823521","wikidata":"https://www.wikidata.org/wiki/Q1662502","display_name":"Certified Information Security Manager","level":5,"score":0.4884731},{"id":"https://openalex.org/C110354214","wikidata":"https://www.wikidata.org/wiki/Q6314146","display_name":"Engineering management","level":1,"score":0.4689177},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.45804},{"id":"https://openalex.org/C182306322","wikidata":"https://www.wikidata.org/wiki/Q1779371","display_name":"Order (exchange)","level":2,"score":0.44371083},{"id":"https://openalex.org/C201359696","wikidata":"https://www.wikidata.org/wiki/Q152361","display_name":"Information Technology Infrastructure Library","level":3,"score":0.4244376},{"id":"https://openalex.org/C139547956","wikidata":"https://www.wikidata.org/wiki/Q6031202","display_name":"Information security standards","level":5,"score":0.4228707},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.40615332},{"id":"https://openalex.org/C121017731","wikidata":"https://www.wikidata.org/wiki/Q11661","display_name":"Information technology","level":2,"score":0.36398375},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3577187},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.35287073},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.33073926},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.20908538},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.18519238},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.1600832},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.15400898},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.103747725},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.097581536},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.07003918},{"id":"https://openalex.org/C10138342","wikidata":"https://www.wikidata.org/wiki/Q43015","display_name":"Finance","level":1,"score":0.0},{"id":"https://openalex.org/C117110713","wikidata":"https://www.wikidata.org/wiki/Q3394676","display_name":"Network security policy","level":4,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/is.2018.8710558","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":4,"referenced_works":["https://openalex.org/W1982848031","https://openalex.org/W2184786010","https://openalex.org/W2328687854","https://openalex.org/W2887974726"],"related_works":["https://openalex.org/W40842196","https://openalex.org/W3194176874","https://openalex.org/W2609802486","https://openalex.org/W2584162156","https://openalex.org/W2483557577","https://openalex.org/W2276722863","https://openalex.org/W203815982","https://openalex.org/W2003676537","https://openalex.org/W2000891179","https://openalex.org/W1495551475"],"abstract_inverted_index":{"The":[0],"security":[1,17,29,45,138,171],"standard":[2,32,67,120],"ISO/IEC":[3,65,98],"27001":[4],"provides":[5,104],"orientations":[6],"to":[7,10,35,50,63,84,110,143,157,162],"support":[8],"organizations":[9,34,61,94,131],"set":[11],"adequate":[12,42],"best":[13],"practices":[14],"in":[15,82],"information":[16,38,137,170],"management,":[18],"specifying":[19],"requirements":[20],"that":[21,130,169],"enable":[22],"the":[23,70,76,86,97,107,113,123,144,178],"appropriate":[24],"selection":[25],"and":[26,46,68,89,115,160,167,175],"implementation":[27],"of":[28,44,59,78,118],"controls.":[30],"This":[31,73],"assists":[33],"protect":[36],"their":[37,41,52],"assets,":[39],"achieve":[40],"levels":[43],"thus":[47],"help":[48],"them":[49],"succeed":[51],"business":[53],"goals.":[54],"Currently,":[55],"an":[56,154],"increasing":[57],"number":[58],"Portuguese":[60,93],"seek":[62],"comply":[64],"27001:2013":[66,99],"obtain":[69],"respective":[71],"certification.":[72],"paper":[74,103],"presents":[75],"result":[77],"a":[79],"research":[80,124],"conducted":[81,125],"order":[83],"detail":[85],"main":[87],"difficulties":[88],"limitations":[90],"evidenced":[91],"by":[92],"while":[95],"meeting":[96],"standard.":[100],"Moreover,":[101],"this":[102,119],"discussion":[105],"on":[106],"results":[108],"obtained,":[109],"better":[111],"understand":[112],"progress":[114],"status":[116],"quo":[117],"implementation.":[121],"From":[122],"it":[126,142],"can":[127],"be":[128],"seen":[129],"are":[132,173],"becoming":[133],"heavily":[134],"concerned":[135],"with":[136],"issues,":[139],"mainly":[140],"due":[141],"recent":[145],"cybersecurity":[146],"incidents":[147],"occurred.":[148],"Additionally,":[149],"certification":[150],"is":[151],"recognized":[152],"as":[153],"important":[155],"instrument":[156],"give":[158],"confidence":[159],"demonstrate":[161],"all":[163],"organizational'":[164],"customers,":[165],"suppliers":[166],"stakeholders":[168],"components":[172],"verified":[174],"organized":[176],"within":[177],"organization.":[179]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2943913887","counts_by_year":[{"year":2023,"cited_by_count":4},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":2}],"updated_date":"2025-01-18T20:32:07.058157","created_date":"2019-05-16"}