EconPapers    
Economics at your fingertips  
 

Development of an Application-Based Framework for Information Security Management in SMEs

Diana Rusu () and Marius Mantulescu
Additional contact information
Diana Rusu: Faculty of Civil Engineering, Transilvania University of Brasov, 500036 Brasov, Romania
Marius Mantulescu: Faculty of Civil Engineering, Transilvania University of Brasov, 500036 Brasov, Romania

Sustainability, 2025, vol. 17, issue 18, 1-22

Abstract: In an increasingly interconnected and sustainability-driven digital landscape, effective risk management and robust information security practices are essential not only for protecting organizational assets but also for ensuring long-term operational resilience and regulatory compliance, especially for small and medium-sized enterprises (SMEs), which aim to grow but have limited resources. This paper presents the development of a practical framework and a supporting application—GestionAVR—for implementing an Information Security Management System (ISMS) that integrates structured risk management processes. The research presents some theoretical insights and practitioners’ input, with a focus on the needs of SMEs. The framework includes a predefined set of categorized risks across four key areas: organizational, personnel, physical, and technological. Designed for usability and adaptability, the GestionAVR application facilitates risk identification, prioritization, monitoring, and continuous improvement. Validated through a case study in the engineering sector, the solution proved to be effective in enhancing decision-making, reducing time spent on planning, and minimizing overlooked vulnerabilities. Future developments include integration of sustainability indicators aligning with recent updates to ISO 27001 standards, AI-based data analysis and automated reporting. This research offers a customizable and cost-effective tool that supports information security and sustainable organizational development.

Keywords: Information Security Management System; risk management; risk identification; application for SMESs (search for similar items in EconPapers)
JEL-codes: O13 Q Q0 Q2 Q3 Q5 Q56 (search for similar items in EconPapers)
Date: 2025
References: Add references at CitEc
Citations:

Downloads: (external link)
https://www.mdpi.com/2071-1050/17/18/8314/pdf (application/pdf)
https://www.mdpi.com/2071-1050/17/18/8314/ (text/html)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:gam:jsusta:v:17:y:2025:i:18:p:8314-:d:1750910

Access Statistics for this article

Sustainability is currently edited by Ms. Alexandra Wu

More articles in Sustainability from MDPI
Bibliographic data for series maintained by MDPI Indexing Manager ().

 
Page updated 2025-09-17
Handle: RePEc:gam:jsusta:v:17:y:2025:i:18:p:8314-:d:1750910