PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
September 18, 2025Sustainability2 citationsOpen Access

Development of an Application-Based Framework for Information Security Management in SMEs

View Full Paper
DRDiana RusuMMMarius Mantulescu

Key Points

  • The framework enhances decision-making and reduces overlooked vulnerabilities in SMEs, supporting their growth.
  • The application integrates structured risk management processes tailored for organizational, personnel, physical, and technological security.
  • Validation through a case study demonstrated effectiveness in planning efficiency and vulnerability mitigation for SMEs.
  • Future developments will align with ISO 27001 standards and include AI-based data analysis for improved reporting.

Abstract

In an increasingly interconnected and sustainability-driven digital landscape, effective risk management and robust information security practices are essential not only for protecting organizational assets but also for ensuring long-term operational resilience and regulatory compliance, especially for small and medium-sized enterprises (SMEs), which aim to grow but have limited resources. This paper presents the development of a practical framework and a supporting application—GestionAVR—for implementing an Information Security Management System (ISMS) that integrates structured risk management processes. The research presents some theoretical insights and practitioners’ input, with a focus on the needs of SMEs. The framework includes a predefined set of categorized risks across four key areas: organizational, personnel, physical, and technological. Designed for usability and adaptability, the GestionAVR application facilitates risk identification, prioritization, monitoring, and continuous improvement. Validated through a case study in the engineering sector, the solution proved to be effective in enhancing decision-making, reducing time spent on planning, and minimizing overlooked vulnerabilities. Future developments include integration of sustainability indicators aligning with recent updates to ISO 27001 standards, AI-based data analysis and automated reporting. This research offers a customizable and cost-effective tool that supports information security and sustainable organizational development.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Rusu et al. (2025) studied this question.

synapsesocial.com/papers/68d462d231b076d99fa624e2https://doi.org/10.3390/su17188314
Ask AI
Helpful
Bookmark
Share
View Full Paper