首页> 外文会议>International conference on business information systems >Information Security Management Systems - A Maturity Model Based on ISO/IEC 27001
【24h】

Information Security Management Systems - A Maturity Model Based on ISO/IEC 27001

机译:信息安全管理系统-基于ISO / IEC 27001的成熟度模型

获取原文

摘要

An Information Security Management System, according with the ISO/IEC 27001 is the set of "that part of the overall management system, based on a business risk approach, to establish, implement, operate, monitor, review, maintain and improve information security". ISO/IEC 27001 defines the requirements and process for implementing an Information Security Management System. However, implementing this standard without a detailed plan can become a burden on organizations. This paper presents a maturity model for the planning, implementation, monitoring and improvement of an Information Security Management System based on ISO/IEC 27001. The purpose of this model is to provide an assessment tool for organizations to use in order to get their current Information Security Management System maturity level. The results can then be used to create an improvement plan which will guide organizations to reach their target maturity level. This maturity model allows organizations to assess their current state of affairs according to the best practices defined in ISO/IEC 27001. The maturity model proposed in this paper is evaluated through a multi-step perspective that is used to confirm that the maturity model makes a useful and novel contribution to the Information Security Management domain by taking in consideration the best practice of the domain.
机译:根据ISO / IEC 27001的信息安全管理系统是“基于业务风险方法,建立,实施,操作,监视,审查,维护和改善信息安全的整个管理系统的一部分”的集合。 。 ISO / IEC 27001定义了实施信息安全管理系统的要求和过程。但是,在没有详细计划的情况下实施此标准可能会成为组织的负担。本文提出了一个基于ISO / IEC 27001的信息安全管理系统规划,实施,监视和改进的成熟度模型。该模型的目的是为组织提供评估工具,以获取其当前信息。安全管理系统的成熟度级别。然后可以将结果用于创建改进计划,该计划将指导组织达到其目标成熟度水平。该成熟度模型允许组织根据ISO / IEC 27001中定义的最佳实践评估其当前状态。本文提出的成熟度​​模型是通过多步评估的,用于确认该成熟度模型是否具有通过考虑该领域的最佳实践,对信息安全管理领域做出了有益而新颖的贡献。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号