首页> 外文会议>International Workshop on Big Data and Information Security >On Developing Information Security Management System (ISMS) Framework for ISO 27001-based Data Center
【24h】

On Developing Information Security Management System (ISMS) Framework for ISO 27001-based Data Center

机译:基于ISO 27001的数据中心开发信息安全管理系统(ISMS)框架的研究

获取原文

摘要

The data center needs a protection both physically and logically to secure information system from any security attacks. Any information security threats like stealing of information, denial of service and unauthorized access can cause an adverse impact on the corporate either loss of revenue, reputation and trust from the customer. Implementing Information Security Management System (ISMS) can help to identify, manage and reduce any information security threats in the data center. One of widely accepted ISMS standard today is ISO 27001. However, to the best of our knowledge, there is no specific ISMS standard that is designed for the data center at this moment. Existing standards such as ISO 27001 are designed to provide general information security that can be applied to different environments. In this paper, we propose an ISMS framework that is specifically designed for the data center to manage the aspect of confidentiality, integrity, and availability of information security. It is an implementation of people, process, and technology concept in protecting information security in the data center. This framework is developed based on ISO 27001, Annex A standard. By implementing this ISMS framework, management could reduce information security threats in the data center and support organization business continuity.
机译:数据中心需要物理和逻辑上的保护,以保护信息系统免受任何安全攻击。诸如信息窃取,拒绝服务和未经授权的访问之类的任何信息安全威胁都可能对公司造成不利影响,无论是收入损失,信誉还是来自客户的信任。实施信息安全管理系统(ISMS)可以帮助识别,管理和减少数据中心中的任何信息安全威胁。 ISO 27001是当今被广泛接受的ISMS标准之一。但是,据我们所知,目前还没有针对数据中心设计的特定ISMS标准。现有标准(例如ISO 27001)旨在提供可应用于不同环境的常规信息安全性。在本文中,我们提出了一个ISMS框架,该框架是专门为数据中心设计的,用于管理机密性,完整性和信息安全性的可用性。它是人员,流程和技术概念在保护数据中心信息安全方面的一种实现。该框架是根据ISO 27001附录A标准开发的。通过实施此ISMS框架,管理人员可以减少数据中心中的信息安全威胁,并支持组织业务连续性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号