首页> 外文会议>Americas conference on information systems;AMCIS 2011 >Model Driven Information Security Management-Evaluating and Applying the Meta Model of ISO 27001
【24h】

Model Driven Information Security Management-Evaluating and Applying the Meta Model of ISO 27001

机译:模型驱动的信息安全管理-评估和应用ISO 27001元模型

获取原文

摘要

Information technology has had a significant impact on business operations and allowed the emergence of new business models. These IT-enabled processes and businesses however depend on secure information systems which need to be managed. The management of information systems security (ISS) is a highly dynamic and complex task due to constant change in the information technology domain. In this paper we propose the use of a meta model to aid ISS managers in setting up a holistic information security management system (ISMS). For this we describe how an adapted meta model of ISO 27001, a security standard for ISMS, can be used to aid with general phases of ISS management. We demonstrate how models can support ISS managers in their endeavors. The paper concludes with a pragmatic evaluation by providing an example of how such a meta model can be operationalized for vulnerability identification, before discussing potential future research.
机译:信息技术对业务运营产生了重大影响,并允许出现新的业务模型。但是,这些支持IT的流程和业务依赖于需要管理的安全信息系统。由于信息技术领域的不断变化,信息系统安全(ISS)的管理是一项高度动态和复杂的任务。在本文中,我们建议使用元模型来帮助ISS管理者建立整体信息安全管理系统(ISMS)。为此,我们描述了如何将经过修改的ISO 27001元模型(ISMS的安全标准)用于ISS管理的一般阶段。我们演示了模型如何支持ISS经理的工作。本文以务实的评估作为结尾,在讨论潜在的未来研究之前,提供了一个示例说明如何将这种元模型用于识别脆弱性的示例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号