The use of ISO/IEC 27001: 2009 to analyze the risk and security of information system assets: case study in xyz, ltd | IEEE Conference Publication | IEEE Xplore