首页> 外文会议>European Conference of Computer Science >Information Security Policy Development and Implementation Piggybacking onto Finnish National Security Auditing Criteria KATAKRI
【24h】

Information Security Policy Development and Implementation Piggybacking onto Finnish National Security Auditing Criteria KATAKRI

机译:信息安全政策开发和实施捎带到芬兰国家安全审计标准卡塔克里

获取原文

摘要

The "weakest link" of security is the human and organizational aspects of information security. Nowadays, risk assessment methods and information security plans and policies are an essential part of many organizations. However, the managerial aspects of information security often remain challenging, especially in emerging technological contexts, and management executives lack an understanding of information security requirements and importance. KATAKRI is a Finnish national security auditing criteria that is based on several information security management system standards and best practices, including four main areas: (1) administrative security, (2) personnel security, (3) physical security, and (4) information security. This multiple case study analysis consists of five individual cases studies that research how KATAKRI is suitable for different types of organizations. The cross-case conclusions examine what type of usability KATAKRI has in information security policy development and implementation in general. The results revealed that organizations have deemed the security policy useful. However, the individual contents and practices of the different security policies differed quite a lot from each other. In particular, the companies found particularly the implementation of security policies within their organizations to be a challenge.
机译:安全的“最弱的链接”是信息安全的人类和组织方面。如今,风险评估方法和信息安全计划和政策是许多组织的重要组成部分。但是,信息安全的管理方面经常保持挑战,特别是在新兴的技术环境中,管理层高管缺乏对信息安全要求和重要性的理解。 Katakri是一项芬兰国家安全审计标准,基于几个信息安全管理系统标准和最佳实践,包括四个主要领域:(1)行政安全,(2)人员安全,(3)物理安全,(4)信息安全。这种多种案例研究分析包括五种单独的案例研究,研究卡塔克里如何适合不同类型的组织。横向案例结论研究了卡特卡里在信息安全政策开发和实施中的可用性类型。结果表明,组织认为安全政策有用。但是,不同安全政策的个人内容和实践彼此相当多。特别是,这些公司特别发现其组织内的安全政策实施成为挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号