IDEAS home Printed from https://ideas.repec.org/a/gam/jsusta/v17y2025i18p8314-d1750910.html
   My bibliography  Save this article

Development of an Application-Based Framework for Information Security Management in SMEs

Author

Listed:
  • Diana Rusu

    (Faculty of Civil Engineering, Transilvania University of Brasov, 500036 Brasov, Romania)

  • Marius Mantulescu

    (Faculty of Civil Engineering, Transilvania University of Brasov, 500036 Brasov, Romania)

Abstract

In an increasingly interconnected and sustainability-driven digital landscape, effective risk management and robust information security practices are essential not only for protecting organizational assets but also for ensuring long-term operational resilience and regulatory compliance, especially for small and medium-sized enterprises (SMEs), which aim to grow but have limited resources. This paper presents the development of a practical framework and a supporting application—GestionAVR—for implementing an Information Security Management System (ISMS) that integrates structured risk management processes. The research presents some theoretical insights and practitioners’ input, with a focus on the needs of SMEs. The framework includes a predefined set of categorized risks across four key areas: organizational, personnel, physical, and technological. Designed for usability and adaptability, the GestionAVR application facilitates risk identification, prioritization, monitoring, and continuous improvement. Validated through a case study in the engineering sector, the solution proved to be effective in enhancing decision-making, reducing time spent on planning, and minimizing overlooked vulnerabilities. Future developments include integration of sustainability indicators aligning with recent updates to ISO 27001 standards, AI-based data analysis and automated reporting. This research offers a customizable and cost-effective tool that supports information security and sustainable organizational development.

Suggested Citation

  • Diana Rusu & Marius Mantulescu, 2025. "Development of an Application-Based Framework for Information Security Management in SMEs," Sustainability, MDPI, vol. 17(18), pages 1-22, September.
  • Handle: RePEc:gam:jsusta:v:17:y:2025:i:18:p:8314-:d:1750910
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/2071-1050/17/18/8314/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/2071-1050/17/18/8314/
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jsusta:v:17:y:2025:i:18:p:8314-:d:1750910. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.