Alfredo Merlet · Open Science Framework 2026 · 2026
DOI: 10.17605/osf.io/9xqd6
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Certification against ISO/IEC 27001 is often treated as a binary proof of security governance. This book argues that the binary reading obscures a more consequential and more measurable phenomenon, the compliance gap: the persistent distance between what a standard formally requires and what an organization is institutionally prepared to sustain once the auditor leaves the room. Building on institutional theory and on the author's prior work on readiness gaps in AI governance, the book develops a taxonomy of compliance gaps (documentary, control, maturity, and cultural-institutional), a structured methodology for conducting a gap analysis, and a discussion of the institutional and sectoral moderators that shape it. The argument is conceptual and methodological rather than empirical: no primary dataset is analyzed.
No comments yet — start the discussion below.