<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Security Audit Process</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Memoona J. Anwar</string-name>
          <email>memoona.anwar@uts.edu.au</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Asif Q. Gill</string-name>
          <email>asif.gill@uts.edu.au</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Henderik A. Proper</string-name>
          <email>erik.proper@list.lu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Information Security, Information Security Audit</institution>
          ,
          <addr-line>Process Maturity, Compliance</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Luxembourg Institute of Science and Technology</institution>
          ,
          <country country="DE">Germany</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>School of Computer Science, University of Technology Sydney</institution>
          ,
          <addr-line>Ultimo NSW</addr-line>
          ,
          <country country="AU">Australia</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>One of the critical aspects of information security management is the security audit, both internal and external audits. The fundamental challenge for organisations is the effective design and implementation of the information security audits to better understand their information security capability. In this paper, we present insights from an action design research (ADR) project and propose a conceptual model to assess the maturity of security audit processes. The results of this research can be used to create an improvement plan, which will guide organisations to reach their target process maturity level. The maturity model proposed in this paper was evaluated by way of feedback workshops in the target organization. The model forms the basis for future work for generalising the research into a formal reference architecture (involving models and principles) for audit process maturity.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The goal of information security is to ensure a sustainable and adequate level of security or protection
for information assets [
        <xref ref-type="bibr" rid="ref20">1</xref>
        ]. To understand security, it is critical for organisations to realise that security
is a process, and not a product [2]. Therefore, it is of prime importance to assess the maturity of
information security practices and procedures within an organisation. As defined by Whitman and
Mattord [3], security assessment means testing a system to determine its compliance with a security
model, security standard, or specific pre-defined metrics. In this context, organisations conduct
information security assessment via internal and external audits against standards or regulations. Hence,
the internal and external audit processes play a critical role in security assessment. Over the years,
information security audits have evolved from an exercise in “box ticking” and reporting faults, to
putting a much stronger emphasis on proactive risk management. However, the remaining challenge is
to determine if the audit process is keeping pace with rapidly changing areas of security risks such as
ransomeware, phishing attacks, cloud jacking, and deepfakes. Organisations with well-planned audit
process are better able to identify security related business risks and underlying systemic weaknesses,
take appropriate corrective actions, and ultimately support continuous improvement. Nevertheless, to
maintain and enhance information security audit’s credibility, its maturity must be measured and
continually improved [4].
      </p>
      <p>An information security audit process involves questioning by an internal or external party, where they
seek implementation evidence for specific controls and processes. In practice, however, questions do
not reveal the facts regarding their implementation. As a result, while these questions are f or the
betterment of all, audits frequently do not detect underlying issues. As such, they may even lead to a
false sense of security. In today’s digital world of ever-present cyber threats, it is unsafe for a business</p>
      <p>2022 Copyright for this paper by its authors.
to approach a security audit as a tick-box exercise; the stakes are too high [5]. Instead, the audit should
be used as an opportunity to build cyber resilience. Limited financial and human resources is an issue
in establishment of efficient security program [6]. To ensure security, it is important to build security
into the process and adapt a security architecture which ensures that regular security related tasks, are
deployed correctly [7]. However, the challenge then becomes to assess the maturity of the audit process.
Process maturity assurance teams have traditionally relied on manual systems, including spreadsheets
and word processing applications, with reporting and communication on an infrequent or ad hoc basis
due to the effort required. They are, therefore, unable to track and respond to changes within the
underlying risk profile of the organisation, particularly in adapting the audit plan. This itself increases
organisational risk by compromising the accuracy of audits, impacting the integrity of organisation,
overlooking potentially significant risks, not informing the top management in timely manner, and not
identifying the needed improvements. This research narrows the gap between theory and practice for
information security management by following the process of audit maturity mo del and by identifying
the benefits of implementing a standard for organisation’s internal audit needs.</p>
      <p>This research was conducted as part of a large action design research (ADR) project [8, 9], which was
performed through the collaboration with industry partner IDZ. IDZ provides electronic identity
verification services across the globe. In provision of its identity verification services, IDZ processes
personal information. The security requirements for organization processing personal information are
very stringent. To ensure compliance with these requirements, IDZ needs to ensure the efficiency and
maturity of security processes within the organization. As part of ideation and problem formula tion,
IDZ highlighted that they do not have any method to assess the maturity of their information security
audit processes, and we must find a comprehensive method, one that is consistent with the IDZ
information security practices. Thus, the IDZ engaged University (coded name: UTX) researchers to
address the following important practice-oriented research question: RQ: How to assess the maturity of
information security audit processes?
As a first step, the project team was selected. This project team involved two researchers from UTX
who actively worked (ADR intervention) with the IDZ team to design the information security audit
maturity model (iSAM2) artefacts for solving the problem (RQ) at hand. The core of the IDZ team
members (5+) comes from business strategy (top management), project delivery (business analyst,
project manager and development team) and privacy &amp; security (internal/external audit ors &amp;
information security manager) areas (see figure 1). As a result of initial research, the ADR team found
that there is no set criterion based upon which the maturity of audit processes can be measured.
Therefore, the initial phase aims to develop a conceptual model for iSAM2 to assess the audit process
maturity. The conceptual model presented in this paper provides the foundations for future
development of logical and physical models for iSAM2.</p>
      <p>Conceptual Design
Logical Design</p>
      <p>Information Security</p>
      <p>Stream (IDZ)
The remainder of the paper is organised as follows. We first present the literature review, based on
which we identify the research gap we aim to address. Next, we discuss the research approach used in
the study. We then present the iSAM2 contextual and conceptual model that explains the key concepts
and relationships for assessing the maturity of audit process. The evaluation of conceptual model is
presented in section 6. Finally, we conclude the paper and present directions for future research.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Literature Review</title>
      <p>The concept of maturity models is increasingly being applied within the field of information systems
as an approach for organisational development or as means of organisational assessment [10]–[12]. In
general, maturity models involve a systematic framework to benchmark an organisation’s performance
as well as continuous improvement processes [13]. The focus of our research is on the development of
a maturity model for information security audits. There are numerous studies that have been conducted
on information security [14]–[17]. Hengstler [16] and Siponen et al. [15] examine the factors related to
normative beliefs, threat appraisal, self-efficacy, and visibility that influence employees’ intention to
comply with information security policies in organizations. Ifinedo [14] assesses the social influence of
changing individual’s thoughts, actions, feelings, attitudes, and behaviors on information security
compliance in organisations. Kim et al. [17] investigate the factors that influence employees’
information security policy compliance behaviors using elements of their “Triandis model”. These
studies have focused primarily on understanding employees’ attitudes, and behavior on information
security in organisations. There is, however, lack of research in better understanding the impact of audit
process maturity on information security in organisations [18]. Information security audit process
maturity is the measure of how close the audit process is to being complete and able of continual
improvement through qualitative measures and feedback.</p>
      <p>
        There are some model based initiatives. As an example, KPMG proposes a Cyber Maturity Assessm ent
[19] for providing an in-depth review of organisational capability to protect information assets and
preparedness against cyber-attacks. However, Cyber Maturity Assessment is focused on maturity of
overall security program not just one process. Saleh [13] developed an information security maturity
model which is intended as a tool to evaluate the ability of organizations to meet the objectives of
security. However, it seems to lack criteria to judge the trustworthiness and relevance of the results.
COBIT5 maturity model is introduced by the Information Systems Audit and Control Association [20].
Information Security Management Maturity Model [21] is used to evaluate the level of security maturity
in an enterprise information system, improve information systems by gap analyzing and prioritizing the
investment process. The Publisher’s Program Overview for Information Security Management
Assistance, known as PRISMA, was presented in 2007 by the NIST7358 [
        <xref ref-type="bibr" rid="ref14">22</xref>
        ]. The Information Security
Maturity Model is another popular maturity model introduced by Woodhouse in 2008 [
        <xref ref-type="bibr" rid="ref16">23</xref>
        ]. Another
security framework has been introduced by IBM called ISF [24]. The Cyber-security Capability
Maturity Model (C2M2) was presented in 2014 [
        <xref ref-type="bibr" rid="ref22">25</xref>
        ]. The model introduces five different dimensions.
A maturity model derived from ISO 27K [26], [27] is introduced by Brotby and Hinson [28], which
covers the 12 domains of this standard. The focus of above mentioned models is one of the following:
risk management [
        <xref ref-type="bibr" rid="ref22">25</xref>
        ]–[28], security policy and plan management [26]–[28], human resource
management [21], [
        <xref ref-type="bibr" rid="ref16">23</xref>
        ], [
        <xref ref-type="bibr" rid="ref22">25</xref>
        ]–[28], physical security management [21], [26]–[28], IT security
management [26]–[28], communication security management [
        <xref ref-type="bibr" rid="ref22">25</xref>
        ], security technology management
[21], [26]–[28], security event and incident management [21], [
        <xref ref-type="bibr" rid="ref14">22</xref>
        ], [
        <xref ref-type="bibr" rid="ref22">25</xref>
        ]–[28] or security audit and
compliance management [21], [
        <xref ref-type="bibr" rid="ref14">22</xref>
        ], [
        <xref ref-type="bibr" rid="ref22">25</xref>
        ]–[28]. To the best of our knowledge there is no model that
focuses on maturity of audit process. The iSAM2 takes a holistic approach to cover all aspects of
information security audit.
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Research Gap</title>
      <p>None of the above reviewed studies focuses on assessing the maturity of information security audit
processes. Hence, there is a need to develop such a model that can help organisations in implementing
the fundamentals of effective internal auditing regardless of industry or sector.</p>
      <p>Assessing the maturity of audit process will help organisations obtain a better view of, and understand
the deviations from, the audit process workflow. This in turn will highlight the information security
risks that organisation might be facing, and how these can be remediated. The main objective of such
maturity model is to identify a baseline to start improving the audit process for quality improvement,
cost reduction and delivery-time reduction. The maturity model then is used in cycles to build
consensus, set the priorities of investment in information security, and finally measure the
implementation progress [29]. Some of the frameworks that we studied come with maturity model such
as COBIT and ISF. Some other frameworks do not have maturity model such as ISO 27001. Hence, in
this paper we build the foundations of iSAM2 based on ISO 27001. The reason for selecting ISO 27001
is because it is an international standard, independent of any specific industry. Furthermore, IDZ is
already ISO 27001 compliant and wanted to validate the model for ISO 27001 as a starting point.
However, the approach proposed in this paper can be adapted to other standards, which is subject to
further research.</p>
      <p>Theoretically, this study contributes to the information systems research by better understanding the
measures of maturity of audit process and how they can be used as a baseline for enhancing information
security in organisations. Practically this study informs information security auditors and policy makers
on the major institutional drivers for influencing information security in organisations. In addition to
implementation challenges, accomplishing best practices in the audit process is needed and it wa s
undertaken in this research in the form of a self-study that organisations would use to measure
effectiveness and efficiency of audit process.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Research Approach</title>
      <p>This research project applied the ADR [8], [9] method for solving the practical design problem of
designing a maturity assessment model for a well-run information security audit. The starting point for
this research was IDZ’s interest in developing a comprehensive yet straightforward and adaptive
framework to address the above research question. We answered this vital practice-oriented research
problem by using the ADR method [8, 9]. This ADR project developed an overall blueprint of the broad
adaptive digital identity reference architecture framework, which is organized into three main
components: assess, design, and evolve [30]–[34]. Before designing the overall reference architecture
as a privacy enabler for identity verification process, IDZ wanted to know how mature their internal
audit process is to identify security risks and gaps accurately. Hence, this project commenced in
November 2018 at the IDZ, Sydney, Australia, and continued until Dec 2020. Researchers from UTX
were approached by the IDZ in 2018 to help in designing a secure digital identity verification
framework. This iSAM2 is part of that broad framework for assessing the effectiveness and efficiency
of information security internal audit process.</p>
      <p>Problem
Formulation</p>
      <p>Build, Intervene &amp;</p>
      <p>Evaluate
(BIE)</p>
      <p>Reflection &amp; Learning
(RL)</p>
      <p>
        Formalisation
of Learning
(FL)
The ADR method is formalized into four stages: problem formulation, build, intervene and evaluate,
reflection and learning, and formalization of learning. The project research problem was initiated by the
IDZ as a strategic initiative (practice driven). In the initiative stage, research problem for the project
was discussed during the research idea workshops and meetings with the IDZ. The idea of developing
the iSAM2 was mutually explored by the IDZ and UTX. The IDZ had the known practical problem in
hand but no known solution. One of the IDZ’s internal review reports highlighted that “there is no
offthe-shelf mean to measure the effectiveness and efficiency of internal audit process”. Therefore, the
challenge is the design and implementation of the iSAM2. Thus, the next step is the proposed iSAM2,
its iterative development and evaluation. In ADR, kernel theories (See Table 1) are used to provide
baseline generic elements for designing context-specific ADR artefacts. The kernel theories used in this
research are adaptive enterprise service system (AESS) [35], design thinking [36], ISO 27001 [
        <xref ref-type="bibr" rid="ref20">1</xref>
        ] and
a model-driven architecture approach [37]. The ADR team combining researchers and industry
professionals applied the AESS framework as a meta-framework in this research project. The AESS
was used because it provides a vendor-independent, layer-based digital ecosystem metamodel, which
was used to inform the development of the iSAM2 for end-to-end digital ecosystem [30]. Figure 2 shows
the approach adopted for this research.
Although iSAM2 is not standard specific however IDZ’s client
requirement is that they should be ISO 27001 certified. Therefore,
we used ISO 27001 as a starting point.
      </p>
      <p>Adaptive enterprise service To design the iSAM2, we needed the reference meta-model. Thus,
system (AESS) we used the AESS, which provided an end-to-end digital
ecosystem view to design the iSAM2. The purpose of the iSAM2 was to
design a reference maturity model with different maturity levels
considering security of humans, technology, facility, and
environment. This has been further explained in detail in the paper (e.g.,
see Fig. 3).</p>
      <sec id="sec-4-1">
        <title>Design thinking (DT) Design thinking offers a balanced approach or mindset of intuition</title>
        <p>and analytical thinking, which was used for the continuous design
or re-design of the iSAM2 in small iterations based on the
feedback loop mechanism. Design thinking is clear in the four stages
of applied ADR.</p>
      </sec>
      <sec id="sec-4-2">
        <title>Model Driven Architecture Model-driven architecture provides a set of guidelines for the</title>
        <p>structuring of specifications, which are expressed as models. The
iSAM2 was organised and explained in terms of these layers.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Information Security Audit Maturity Model-Conceptual Model</title>
      <p>The ADR team (See Figure 1) at the IDZ engaged in recursive adaptive cycles of design innovation and
mutual learnings among the project work streams at conceptual, logical, and physical architecture
design layers (Model Driven Architecture layers based on architecture kernel theory). The scope of this
research paper is limited to conceptual model only. The researchers from UTX largely contributed to
the conceptual design and mutual learnings through their knowledge of design theory and technological
advances (knowledge stream – Figure 1), while the IDZ practitioners including supporting organisations
largely contributed through their practical knowledge of IDZ work practices and the environment in
which the IDZ operates (integration of research and practice). Users were involved in all aspects of this
process. The knowledge stream (researchers) was mainly responsible for the conceptual iSAM2
architecture model. The information security stream (practitioners) was responsible for turning the
conceptual architecture into the logical iSAM2 model, and the business, IT and auditing stream
(practitioners) was responsible for turning the logical iSAM2 into the physical iSAM2 or implementation
(planning, fieldwork and reporting). These three streams also include users. The next section presents
the contextual and conceptual model for iSAM2.
5.1.</p>
    </sec>
    <sec id="sec-6">
      <title>Contextual Model (Level-0)</title>
      <p>Figure 3 illustrates the iSAM2 architecture context model (level 0) for the IDZ, which highlights the four
major architecture building blocks of the IDZ: audit, compliance, information security framework and
asset. This model shows that security compliance is based on information secur ity framework and is
assured by security audit (both internal &amp; external). Information security framework is developed and
maintained to make organisational assets (identity information in IDZ’s context) secure. Hence, it is
very important to have an efficient and effective audit process in place to measure organisation’s
iSAM2</p>
      <p>Uses
Audit</p>
      <p>Assured By</p>
      <p>Compliance
security preparedness correctly. These four building blocks were detailed in terms of conceptual (level
1), logical (level 2) and physical models (level 3). In this paper, we present the d etails of contextual and
conceptual models as examples.</p>
      <p>Based On</p>
      <p>Information Security</p>
      <p>Framework</p>
      <p>Secures</p>
      <p>Asset
The iSAM2 model is based on the theoretical AESS metamodel. In practice, an architecture is designed
using some relevant reference or metamodel; thus, in this project, we used the vendor independent
AESS metamodel as a reference model to develop the iSAM2 architecture for the IDZ context.
This metamodel was used due to its higher relevance to IDZ’s identity ecosystem. The identity
ecosystem is a user-centric (HUMAN) online environment (ENVIRONMENT) – a set of processes,
technologies (TECHNOLOGY), policies and agreed upon standards that secu rely (PRIVACY &amp;
Maturity Assessment
Uses</p>
      <p>Audit</p>
      <p>Assured By
Compliance</p>
      <p>Based On</p>
      <p>Information Security
Information Security</p>
      <p>Framework</p>
      <p>Secures
Asset</p>
      <p>Human Security
Technology Security</p>
      <p>Facility Security
Environment Security
SECURITY) supports transactions ranging from anonymous to fully -authenticated and from low to
high value based upon data stored in secure data centers (FACILITY) [38], [39]. This section discusses
the iSAM2 conceptual architecture models for information security audit maturity.</p>
      <p>Audit and compliance are both very essential functions in an organisation. Audit and compliance have
risen in importance, both signifying critical control components of information security. The compliance
function is meant to reasonably ensure that the company is complying with all applicable laws, rules,
and regulations, as well as internal codes of conduct, policies and procedures managed via company’s
information security framework. The audit function is designed to monitor and evaluate the company’s
internal control environment as to its adequacy, efficiency, and effectiveness. There are two types of
conceptual security models at level 1: security classification model (See Figure 4) and security concepts
&amp; relationship model (See Figure 5). The information security building block is core to the security
architecture and was classified in terms of human, technology, facility, and environment security. The
security concepts and relationship conceptual model described the relationship between these layers.
There is a two-way relationship between human security, technology security and facility security. The
human, technology and facility security are dependent on environment security in which they operate.
The security of environment in turn is governed by multiple factors such as changing risk, information
security needs, external context, control objectives policies, laws, regulations, and compliance
requirements.</p>
    </sec>
    <sec id="sec-7">
      <title>6. iSAM2 Evaluation</title>
      <sec id="sec-7-1">
        <title>Description</title>
        <p>The number of concepts present in
the model corresponds to the
number of concepts demanded by the
user in their requirements.
iSAM2 is useful for filling the
research gaps
iSAM2 is general and is not attached
to one context or situation.
Furthermore, it can adapt to multiple
circumstances and be applied with
different technology stacks.</p>
        <sec id="sec-7-1-1">
          <title>Usefulness</title>
        </sec>
        <sec id="sec-7-1-2">
          <title>Generalization</title>
          <p>During the workshop, the researchers presented the research problem and gaps identified by t he
literature review. The presentation ran for 30 minutes. After the presentation, the researcher facilitated
a brainstorming session to identify the alignment between IDZ’s needs and the research problem for
this research project. Table 3 details the first design workshop together with the workshop objectives,
role and responsibilities and feedback and comments from the participants.</p>
          <p>At the end of the design workshop all participants agreed that the concepts and relationships in the
iSAM2 conceptual model fulfill the criteria of completeness, usefulness, and generalization. The overall
goal of this research was to develop and test design principles and practices to address the identified
research problem assessing the effectiveness and efficiency of the in ternal audit via maturity model
design and implementation. This paper only presents the details of first iteration of iSAM2 development,
however as a result of feedback workshop two important design principals were emerged i.e., critical
asset identification and setting out clear information security objectives. The design principals will be
further evaluated on formalizing the learning and final feedback at the end of the project. The ADR
team is ready to start the next iteration of build, intervene, and evaluate and reflection and learning. the
results of further iteration will be presented as future work.
The researcher of this project is responsible for explaining the
model concepts and relationships, educating, and facilitating the
design decisions, and documenting the feedback
• top management
• business analyst
• project manager
• development team
• internal/external auditors
• information security manager
iSAM2 Conceptual Model</p>
        </sec>
      </sec>
      <sec id="sec-7-2">
        <title>Comment/Suggestion/Feedback</title>
      </sec>
      <sec id="sec-7-3">
        <title>Criteria</title>
        <p>“The existing audit procedure for IDZ,
whilst efficient and seamless, must be
improved in order to maintain and
extend compliance status within the
industry.”</p>
        <sec id="sec-7-3-1">
          <title>Usefulness</title>
        </sec>
        <sec id="sec-7-3-2">
          <title>Applicability</title>
          <p>“IDZ is seeking to harness the poten- Generalization
tial of new global technology trends
involving biometrics and blockchain.</p>
          <p>Incorporating these technologies into
enhanced applications and efficient
operations that its’ clients can
leverage will open doors for
implementation of new global standards. The
model covers the foundational
concepts of mostly standards.”
“With changing technological and Usefulness
regulatory landscapes, the audit and Generalization
compliance requirements will change, completeness
the models covers all aspects of
technology as well as environmental
changes including legal. Which
implies its adaptability.”</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>7. Conclusion and Future Work</title>
      <p>In this research, we address a practice-oriented research problem by applying the ADR method for
assessing the maturity of information security audit process using Information Security Audit Maturity
Model (iSAM2). The scope of this paper is limited to the contextual and conceptual model of iSAM2.
The iSAM2 is a novel concept in the area of process maturity assessment. The iSAM2 will help in
identifying key concepts and their relationships to be considered when assessing the maturity of the
audit process. In order to assess the maturity of audit process, organisations can proactively identify the
risks associated with the key concepts and escalate through defined path to the stakeholders in
coordination with external and internal auditors. This is research in progress paper, which sets the foundation
for further evaluation and formalization of the results into a reference model and principles for audit
maturity, which is currently a gap both in literature and practice. The results of this paper conclude that
for an audit process to be mature, it must be complete in its usefulness, reliable in information and
continuously improving. The conceptual model as presented in this paper was developed during first
iteration of ADR’s BIE (Build, Iterate, Evaluate) cycle (See Figure 2). Further iterations of BIE in this
project will be reported in future research communications.
8. References</p>
      <p>G. Disterer, “ISO/IEC 27000, 27001 and 27002 for Information Security Management,” J. Inf.
Secur., vol. 4, pp. 92–100, 2013, doi: 10.4236/jis.2013.42011.</p>
      <p>C. Jackson, Network security auditing. Cisco Press, 2010.</p>
      <p>M. E. Whitman and H. J. Mattord, Principles of Information Security. 2011.</p>
      <p>F. Doig, “The all-important link between audit maturity and risk management,” 2019.
https://www.ideagen.com/thought-leadership/blog/the-all-important-link-between-auditmaturity-and-risk-management (accessed Nov. 17, 2021).</p>
      <p>M. Vunk, N. Mayer, and R. Matulevičius, “A framework for assessing organisational it
governance, risk and compliance,” in Communications in Computer and Information Science,
2017, vol. 770, pp. 337–350, doi: 10.1007/978-3-319-67383-7_25.</p>
      <p>N. Mayer, “A cluster approach to security improvement according to ISO/IEC 27001,” 2010.
[14]</p>
      <p>P. Ifinedo, “Information systems security policy compliance: An empirical study of the effects
of socialisation, influence, and cognition,” Inf. Manag., vol. 51, no. 1, pp. 69–79, 2014, doi:
10.1016/j.im.2013.10.001.
[16] S. Hengstler, “Culture matters - A cross cultural examination of information security behavior
theories,” in 16th International Conference on Wirtschaftsinformatik, 2021, vol. 2966, pp. 57–
71.</p>
      <p>A. Buecker, M. Borrett, C. Lorenz, and C. Powers, “Introducing the IBM Security Framework
and IBM Security Blueprint to Realize Business-Driven Security,” pp. 1–80, 2010, Accessed:
Nov. 17, 2021. [Online]. Available:
https://books.google.com/books?hl=en&amp;lr=&amp;id=K3bJAgAAQBAJ&amp;oi=fnd&amp;pg=PP1&amp;dq=Usi
ng+the+IBM+Security+Framework+and+IBM+Security+Blueprint+to+Realize+BusinessDriven+Security,+in+ibm’,+2013.&amp;ots=70p6pzKxb2&amp;sig=pSMbhHbwsnnIXvbPmn6bwcOxF
Ek.</p>
      <p>U.S. Department of Energy, “Cybersecurity Capability Maturity Model (C2M2) | Department
of Energy,” 2014. Accessed: Nov. 17, 2021. [Online]. Available:
https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2.</p>
      <p>
        N. Halvorson, “Information Risk Management,” in Information Security Management
Handbook, Sixth Edition, Volume 2, 2008, pp. 71–81.
[27] ISO27002Security, “ISO/IEC 27002 code of practice,” ISO27002Security, 2017.
https://www.iso27001security.com/html/27002.html (accessed Nov. 17, 2021).
[15]
[17]
[18]
[19]
[20]
[21]
[24]
[
        <xref ref-type="bibr" rid="ref22">25</xref>
        ]
[26]
[28]
[29]
[30]
[31]
[32]
      </p>
      <p>W. K. Brotby and G. Hinson, “- Why Measure Information Security?,” in PRAGMATIC
Security Metrics, 2013, pp. 32–47.</p>
      <p>KPMG, “Transforming Internal Audit: A Maturity Model from Data Analytics to Continuous
Assurance,” 2015.</p>
      <p>M. J. Anwar and A. Q. Gill, “A review of the seven modelling approaches for digital
ecosystem architecture,” in Proceedings - 21st IEEE Conference on Business Informatics, CBI
2019, Jul. 2019, vol. 1, pp. 94–103, doi: 10.1109/CBI.2019.00018.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>S. H.</given-names>
            <surname>Amer</surname>
          </string-name>
          and
          <string-name>
            <given-names>J. A.</given-names>
            <surname>Hamilton</surname>
          </string-name>
          , “
          <article-title>Understanding security architecture,”</article-title>
          <source>in Proceedings of the 2008 Spring Simulation Multiconference, SpringSim'08</source>
          ,
          <year>2008</year>
          , pp.
          <fpage>335</fpage>
          -
          <lpage>342</lpage>
          , doi: 10.1145/1400549.1400596.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <given-names>A. Q.</given-names>
            <surname>Gill</surname>
          </string-name>
          and E. Chew, “
          <article-title>Configuration information system architecture: Insights from applied action design research</article-title>
          ,” Inf. Manag., vol.
          <volume>56</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>507</fpage>
          -
          <lpage>525</lpage>
          ,
          <year>2019</year>
          , doi: 10.1016/j.im.
          <year>2018</year>
          .
          <volume>09</volume>
          .011.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>M. K. Sein</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          <string-name>
            <surname>Henfridsson</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Purao</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Rossi</surname>
            , and
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Lindgren</surname>
            , “Action design research,” MIS
            <given-names>Q.</given-names>
          </string-name>
          <string-name>
            <surname>Manag</surname>
          </string-name>
          . Inf. Syst., vol.
          <volume>35</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>37</fpage>
          -
          <lpage>56</lpage>
          ,
          <year>2011</year>
          , doi: 10.2307/23043488.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>Ahern</given-names>
            <surname>Dennis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Aaron</surname>
          </string-name>
          , and T. Richard, CMMI®
          <article-title>Distilled: A Practical Introduction to Integrated Process Improvement</article-title>
          ,
          <source>Third Edition</source>
          , vol.
          <volume>39</volume>
          .
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <given-names>T.</given-names>
            <surname>Mettler</surname>
          </string-name>
          and
          <string-name>
            <given-names>P.</given-names>
            <surname>Rohner</surname>
          </string-name>
          , “
          <article-title>Situational maturity models as instrumental artifacts for organizational design</article-title>
          ,
          <source>” Proc. 4th Int. Conf. Des. Sci. Res. Inf. Syst. Technol. DESRIST '09</source>
          ,
          <year>2009</year>
          , doi: 10.1145/1555619.1555649.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>M. B. Chrissis</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Konrad</surname>
            , and
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Shrum</surname>
          </string-name>
          ,
          <article-title>CMMI - Guidelines for process integration and product development</article-title>
          .
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <surname>M. F. Saleh</surname>
          </string-name>
          , “Information Security Maturity Model,”
          <string-name>
            <surname>Int</surname>
          </string-name>
          .
          <source>J. Comput. Sci. Secur</source>
          ., vol.
          <volume>5</volume>
          , no.
          <issue>3</issue>
          , p.
          <fpage>21</fpage>
          ,
          <year>2011</year>
          , Accessed: Nov.
          <volume>17</volume>
          ,
          <year>2021</year>
          . [Online]. Available: https://citeseerx.ist.psu.edu/viewdoc/download?doi
          <source>=10.1.1.221.1617&amp;rep=rep1&amp;type=pdf#pa ge=26.</source>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <given-names>M.</given-names>
            <surname>Siponen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Pahnila</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Mahmood</surname>
          </string-name>
          , “
          <article-title>Compliance with information security policies: An empirical investigation,” Computer (Long</article-title>
          . Beach. Calif)., vol.
          <volume>43</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>64</fpage>
          -
          <lpage>71</lpage>
          ,
          <year>2010</year>
          , doi: 10.1109/
          <string-name>
            <surname>MC</surname>
          </string-name>
          .
          <year>2010</year>
          .
          <volume>35</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <surname>D.-J. Kim</surname>
            ,
            <given-names>I.-H.</given-names>
          </string-name>
          <string-name>
            <surname>Hwang</surname>
          </string-name>
          , and J.-S. Kim, “
          <article-title>A Study on Employee's Compliance Behavior towards Information Security Policy : A Modified Triandis Model,”</article-title>
          <string-name>
            <given-names>J.</given-names>
            <surname>Digit</surname>
          </string-name>
          . Converg., vol.
          <volume>14</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>209</fpage>
          -
          <lpage>220</lpage>
          ,
          <year>2016</year>
          , doi: 10.14400/jdc.
          <year>2016</year>
          .
          <volume>14</volume>
          .4.209.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <given-names>A.</given-names>
            <surname>Vance</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Siponen</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Pahnila</surname>
          </string-name>
          , “
          <article-title>Motivating IS security compliance: Insights from Habit and Protection Motivation Theory,”</article-title>
          <string-name>
            <surname>Inf. Manag.</surname>
          </string-name>
          , vol.
          <volume>49</volume>
          , no.
          <issue>3-4</issue>
          , pp.
          <fpage>190</fpage>
          -
          <lpage>198</lpage>
          ,
          <year>2012</year>
          , doi: 10.1016/j.im.
          <year>2012</year>
          .
          <volume>04</volume>
          .002.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <string-name>
            <surname>KPMG</surname>
          </string-name>
          , “
          <article-title>The role of internal audit in cyber security readiness</article-title>
          ,”
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          <string-name>
            <surname>ISACA</surname>
          </string-name>
          , “
          <article-title>A Business Framework for the Governance and Management of Enterprise IT</article-title>
          .”
          <year>2012</year>
          , Accessed: Nov.
          <volume>17</volume>
          ,
          <year>2021</year>
          . [Online]. Available: http://linkd.in/ISACAOfficial.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          The Open Group,
          <string-name>
            <surname>Open Information Security Management Maturity Model (O-ISM3</surname>
            <given-names>)</given-names>
          </string-name>
          ,
          <source>Version 2.0</source>
          .
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [22] PRISMA, “
          <article-title>Program Review for Information Security Assistance</article-title>
          | CSRC,”
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          https://csrc.nist.rip/library/NIST IR 7358.pdf (accessed
          <year>Nov</year>
          .
          <volume>17</volume>
          ,
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>S.</given-names>
            <surname>Woodhouse</surname>
          </string-name>
          , “
          <article-title>An ISMS (im)-maturity capability model</article-title>
          ,”
          <source>in Proceedings - 8th IEEE International Conference on Computer and Information Technology Workshops, CIT Workshops</source>
          <year>2008</year>
          ,
          <year>2008</year>
          , pp.
          <fpage>242</fpage>
          -
          <lpage>247</lpage>
          , doi: 10.1109/CIT.
          <year>2008</year>
          .Workshops.
          <volume>46</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          <string-name>
            <given-names>M.</given-names>
            <surname>Anwar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gill</surname>
          </string-name>
          , and G. Beydoun, “
          <article-title>A review of Australian information privacy laws and standards for secure digital ecosystems</article-title>
          ,
          <source>” ACIS 2018 Proc., Jan</source>
          .
          <year>2018</year>
          , Accessed: Oct.
          <volume>10</volume>
          ,
          <year>2022</year>
          . [Online]. Available: https://aisel.aisnet.org/acis2018/36.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          <string-name>
            <given-names>M.</given-names>
            <surname>Anwar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gill</surname>
          </string-name>
          , and G. Beydoun, “
          <article-title>Using Adaptive Enterprise Architecture Framework for Defining the Adaptable Identity Ecosystem Architecture,” ACIS 2019 Proc</article-title>
          .,
          <string-name>
            <surname>Jan</surname>
          </string-name>
          .
          <year>2019</year>
          , Accessed: Oct.
          <volume>10</volume>
          ,
          <year>2022</year>
          . [Online]. Available: https://aisel.aisnet.org/acis2019/94.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          <string-name>
            <surname>M. J. Anwar</surname>
            ,
            <given-names>A. Q.</given-names>
          </string-name>
          <string-name>
            <surname>Gill</surname>
            ,
            <given-names>F. K.</given-names>
          </string-name>
          <string-name>
            <surname>Hussain</surname>
            , and
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Imran</surname>
          </string-name>
          , “
          <article-title>Secure big data ecosystem architecture: challenges and solutions</article-title>
          ,”
          <string-name>
            <surname>Eurasip</surname>
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Wirel</surname>
          </string-name>
          . Commun. Netw., vol.
          <year>2021</year>
          , no.
          <issue>1</issue>
          , pp.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          1-
          <fpage>30</fpage>
          , Dec.
          <year>2021</year>
          , doi: 10.1186/S13638-021-01996-2/TABLES/13.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          <string-name>
            <surname>M. J. Anwar</surname>
            ,
            <given-names>A. Q.</given-names>
          </string-name>
          <string-name>
            <surname>Gill</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Farookh</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          <string-name>
            <surname>Dr</surname>
          </string-name>
          , and G. Beydoun, “
          <article-title>Adaptive Digital Identity Verification Reference Architecture (ADIVRA) Framework</article-title>
          ,” Sydney,
          <year>2021</year>
          . Accessed: Jul.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          25,
          <year>2022</year>
          . [Online]. Available: http://hdl.handle.net/10453/153306.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          <string-name>
            <given-names>A. Q.</given-names>
            <surname>Gill</surname>
          </string-name>
          ,
          <source>Adaptive Cloud Enterprise Architecture</source>
          , vol.
          <volume>4</volume>
          .
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          <string-name>
            <given-names>M.</given-names>
            <surname>Mandviwalla</surname>
          </string-name>
          , “
          <article-title>Generating and justifying design theory,”</article-title>
          <string-name>
            <given-names>J.</given-names>
            <surname>Assoc</surname>
          </string-name>
          . Inf. Syst., vol.
          <volume>16</volume>
          , no.
          <issue>5</issue>
          , pp.
          <fpage>314</fpage>
          -
          <lpage>344</lpage>
          ,
          <year>2015</year>
          , doi: 10.17705/1jais.
          <fpage>00397</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          OMG.Org, “
          <article-title>Model Driven Architecture (MDA</article-title>
          ) | Object Management Group,” Https://Www.Omg.Org/Mda/,
          <year>2019</year>
          . https://www.omg.org/mda/ (accessed Nov.
          <volume>17</volume>
          ,
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          <string-name>
            <given-names>United</given-names>
            <surname>States</surname>
          </string-name>
          <string-name>
            <surname>Government</surname>
          </string-name>
          , “National Strategy for Trusted Identities in Cyberspace,” Online, p.
          <fpage>25</fpage>
          ,
          <year>2011</year>
          , Accessed: Nov.
          <volume>17</volume>
          ,
          <year>2021</year>
          . [Online]. Available: https://archive.epic.org/privacy/nstic.html.
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          <string-name>
            <given-names>A. Q.</given-names>
            <surname>Gill</surname>
          </string-name>
          , “
          <article-title>Applying agility and living service systems thinking to enterprise architecture,” in Decision Management: Concepts, Methodologies, Tools, and Applications</article-title>
          , vol.
          <volume>1</volume>
          -
          <issue>4</issue>
          ,
          <year>2017</year>
          , pp.
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          <string-name>
            <given-names>J. L.</given-names>
            <surname>Wynekoop</surname>
          </string-name>
          and
          <string-name>
            <given-names>N. L.</given-names>
            <surname>Russo</surname>
          </string-name>
          , “
          <article-title>Studying system development methodologies: an examination of research methods,”</article-title>
          <string-name>
            <surname>Inf. Syst. J.</surname>
          </string-name>
          , vol.
          <volume>7</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>47</fpage>
          -
          <lpage>65</lpage>
          , Jan.
          <year>1997</year>
          , doi: 10.1046/J.
          <fpage>1365</fpage>
          -
          <lpage>2575</lpage>
          .
          <year>1997</year>
          .00004.X.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>