错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cybersecurity Risk Audit: A Systematic Literature Review

  • Isaac D. Sanchez-Garcia,
  • Angel M. Rea-Guaman,
  • Tomás San Feliu Gilabert,
  • Jose A. Calvo-Manzano

摘要

One of the stages of cybersecurity risk management is monitoring and review. This stage is part of the continuous improvement of a cybersecurity risk management system. This article aims to carry out a state-of-the-art cybersecurity risk audit where common objectives are established, and the guidelines of the cybersecurity risk audit are analyzed. The SLR was carried out considering the studies of the last ten years (2012–2022), from which 23 studies that mentioned cybersecurity risk audit objectives and guidelines were identified. The relationships among different objectives of cybersecurity risk audit were identified. In addition, the most used cybersecurity risk audit guidelines (e.g., the ISO 27000 family and the NIST CSF), and their application scopes were also identified. Additionally, it was identified that the cybersecurity risk audit approaches could be classified in the primary studies: (1) strategic, (2) technical, and (3) process. Finally, it is considered that the cybersecurity risk audit can be complemented by considering attributes of the SOX-COSO and IAASB internal control guides.