VLDB 2026 Research / reviewers in the wild / expert
Mona Mirtsch
dblp:267/0112
· DBLP profile ↗
2ranked-venue papers
2as first author
2since 2021 · last 2026
0000-0002-2036-4579ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Certification as a compensation mechanism for weak regulation? Exploring the diffusion of the international standard ISO/IEC 27001 for information security managementabstractSafeguarding information security has become a key managerial responsibility. The standard “Information security, cybersecurity and privacy protection - Information security management systems - Requirements” (ISO/IEC 27001) specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). It provides a systematic approach to managing sensitive information, ensuring its confidentiality, integrity, and availability through risk management and security controls. While the number of valid certifications has grown significantly over time, adoption rates vary widely across countries. Drawing on signaling theory, we present the first comprehensive global study of ISO/IEC 27001 diffusion, with a particular focus on the influence of regulatory frameworks and international trade. Based on regression analyses covering 128 countries having implemented ISO/IEC 27001 between 2006 and 2017, our findings suggest that organizations may use ISO/IEC 27001 certification as a signaling mechanism, especially in environments with less stringent regulatory frameworks. Mona Mirtsch, Jakob Pohlisch, Knut Blind |
Comput. Secur. | 1 |
| 2021 | Information security management in ICT and non-ICT sector companies: A preventive innovation perspectiveabstractDespite the growing dependence of companies on information technology and the increasingly negative impact of security incidents worldwide, there is little research on the management of information security at the company level. This paper seeks to expand knowledge on the implementation of an information security management system based on the widely used international standard ISO/IEC 27001. We present motives, experienced impacts, and obstacles related to ISO/IEC 27001 implementation using data from a survey of 125 ISO/IEC 27001 certified companies in Germany. Since adoption rates vary between ICT and non-ICT sector companies, we highlight sector-related variations. We classify the adoption of this standard as a preventive organizational innovation and apply Structural Equation Modeling to unearth explanations for the comparatively low adoption of this management system standard among companies outside the ICT sector. We, therefore, derive recommendations for policymakers, standardization, and certification bodies to foster its diffusion. Mona Mirtsch, Knut Blind, Claudia Koch, Gabriele Dudek |
Comput. Secur. | 1 |