In this paper we attempted to identify relevant concepts of information security in the ISO 27001 standard to achieve insight into its structure and possibly criteria of quality such as comprehensiveness. As a methodological foundation we applied QDA to enhance transparency and traceability of the metamodeling procedure and, furthermore, showed that metamodels can assist in the analysis and comparison of multiple ontologies.