Pedro Solana-González, Adolfo Alberto Vanti, Karen Hackbart Souza Fontana


Information security is a current issue of protection of information assets that considers significant variables of a strategic, organizational and IT governance nature, and that requires to analyze the compliance with international standards that regulate business actions. In this way, the work analyzes institutional compliance to improve information security applying the Analytic Hierarchy Process methodology to the specific practices defined in ISO/IEC 27002:2013. Expert Choice has been used as Decision Support Systems that has generated as a result the ranking of priorities of the criteria and alternatives used in the decisional process, been applied later in a medium-sized Brazilian industrial company. The results identify the main security practice related to the independent critical analysis of information security.


Information security, Compliance, Security practices, Analytic hierarchy process, Decision support system

