In this respect the motivation of our research is analytic in
nature, as we try to determine the applicability of the
metamodel for phases of information security management. In
the following, we are going to use the metamodel of ISO/IEC
27001 for an analytical purpose, e.g. to evaluate for
comprehensiveness or completeness. Figure 1 depicts the
overall methodology of our research program and the position
of our research presented in this paper.