@inproceedings{3727e857e01740ba9ea831898d5cca4c,
title = "Addressing SME Characteristics for Designing Information Security Maturity Models",
abstract = "This paper identifies the effects of small and medium-sized enterprises{\textquoteright} (SME) characteristics on the general design principles for maturity models in the information security domain. The purpose is to guide the research on information security maturity modelling for SMEs that will fit in form and function for their capability assessment and development purposes, and promote organizational learning and development. This study reviews the established frameworks of general design principles for maturity models and projects the design requirements of our envisioned information security maturity model for SMEs. Maturity models have different purposes of uses (descriptive, prescriptive and comparative) and design principles with respect to these purposes of uses. The mapping of SME characteristics and design principles facilitates the development of an information security maturity model that systematically integrates the desired qualities and components addressing SME characteristics and requirements.",
keywords = "Information security, Maturity model, Assessment, Process improvement, Organisational learning, SME",
author = "{Yigit Ozkan}, B. and M.R. Spruit",
year = "2020",
month = aug,
doi = "10.1007/978-3-030-57404-8_13",
language = "English",
isbn = "978-3-030-57403-1",
series = "IFIP Advances in Information and Communication Technology",
publisher = "Springer",
editor = "Clarke, {Nathan } and Furnell, {Steven }",
booktitle = "Human Aspects of Information Security and Assurance",
address = "Germany",
}