Adoption of ISO/IEC 27001 in Mozambique: Challenges, Opportunities, and Implications for Information Security Governance
The increasing digitalization of economic and social activities has intensified the importance of information security as a strategic component of organizational governance and digital resilience. In this context, ISO/IEC 27001 has emerged as the leading international standard for implementing Information Security Management Systems (ISMS), supporting organizations in managing cybersecurity risks, enhancing regulatory compliance, and strengthening digital trust. Despite its global relevance, limited research has examined the factors influencing ISO/IEC 27001 adoption in developing countries, particularly within the Mozambican context. This study analyzes the challenges, opportunities, and implications associated with the adoption of ISO/IEC 27001 in Mozambique. An integrative literature review and documentary analysis were conducted, drawing upon scientific publications, institutional reports, regulatory frameworks, and policy documents. The analysis was guided by the Technology–Organization–Environment (TOE) framework and the Technology Acceptance Model (TAM), enabling the examination of technological, organizational, environmental, and behavioral determinants of adoption. The findings indicate that ISO/IEC 27001 adoption is influenced by a combination of factors, including technological infrastructure, organizational capabilities, financial resources, regulatory conditions, management commitment, and stakeholders’ perceptions of usefulness and implementation complexity. Key barriers include the shortage of qualified cybersecurity professionals, implementation and certification costs, infrastructural limitations, and low levels of cybersecurity maturity. Conversely, significant opportunities were identified, including enhanced digital trust, improved regulatory compliance, stronger risk management practices, increased organizational competitiveness, and greater resilience against cyber threats. The study concludes that ISO/IEC 27001 represents a strategic instrument for strengthening information security governance in Mozambique. The findings contribute to the literature on information security governance and technology adoption by integrating the TOE and TAM frameworks within a developing-country context. Practical recommendations are provided for organizations, policymakers, and regulatory institutions seeking to foster cybersecurity maturity and sustainable digital transformation.