MARATTO

article · Engineering Technology & Applied Science Research

Designing an Ontology-Based Framework for ISO 27002-Based Information Security Risk Management

Abstract

Information Security Risk Management (ISRM) is an essential requirement for organizations seeking to ensure the governance and protection of their information assets. Ontology-based knowledge representation has emerged as a promising solution to address information security challenges, as it enables the formalization of concepts, relationships, and constraints within a given domain. This paper proposes an ontology-based framework aligned with the ISO/IEC 27002 standard. The approach consists of extracting relevant concepts from textual sources using UML modeling and TF-IDF filtering, and representing them in OWL using the Protégé environment. The resulting ontology formally captures key ISRM entities—including assets, threats, vulnerabilities, risks, controls, and monitoring mechanisms. The ontology was validated using the FACT++ reasoner to assess consistency and semantic completeness. The results show that the proposed model ensures traceability across ISO/IEC 27002 control families, supports governance alignment, and improves visibility across risk treatment processes.

Research topics

  • Information and Cyber Security
  • Access Control and Trust
  • Software System Performance and Reliability

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.48084/etasr.15794

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.