首页> 外文会议>European Conference on Information Warfare and Security >Information Security - Military Standards Versus ISO 27001: A Case Study in a Portuguese Military Organization
【24h】

Information Security - Military Standards Versus ISO 27001: A Case Study in a Portuguese Military Organization

机译:信息安全 - 军事标准与ISO 27001:葡萄牙军事组织的案例研究

获取原文

摘要

The objective of this paper is to present a Case Study conducted in a Portuguese military organization, which seeks to answer the following research questions: (1) what are the most relevant dimensions and categories of information security controls applied in military organizations? (2) What are the main scenarios of information security incidents that are expected to occur? (3) What is the decision process used for planning and selection information security controls? Current trends in technological advances impose new security requirements to information systems. This is true for all application domains, including military and especially concerning their unavoidable links to cyberspace. However, most of the time these information systems are specified under rules adapted to a different environment, what can result in unexpected and dangerous security flows. This study aims to evaluate how the military doctrine of the Portuguese Army limits or promotes the implementation of the international standard ISO / IEC 27001 (information systems security management) and simultaneously to propose a formal method for the selection and management of information security controls, based on that standard and aligned with the military organization. This Case Study consists of three phases: the first phase involves the collection and analysis of key documentation of the organization; in a second phase, a questionnaire was applied in the military organization, to three distinct groups - decision-makers, information security specialists, and employees with functions specifically linked to information use; and finally, in a third phase, interviews with specialists are used to validate the results obtained from the other phases. This study reveals that (1) information security within the military organization is built on the basis of physical and human attack vectors, and targeting the infrastructure that supports the flow of information in the organization (i.e. Information Systems), (2) the information security controls applied in the military organization are included in ISO 27001; (3) planning and selection of applied information security controls are made by decision makers and information security specialists, aiming to protect mainly integrity of digital information. It appears that specialists impose their planning options essentially inferring knowledge from analogies (like following guidelines), or rather, seeking to select and retrieve past successful information security cases, i.e. similar scenarios concerning situations under planning and that may (likely) lead to the selection and implementation of the most efficient information security controls.
机译:本文的目的是介绍一个案例研究葡萄牙军事组织,其目的是回答以下研究问题进行:(1)什么是信息安全控制最相关的尺寸和类别的军事组织实施? (2)什么是被期望发生信息安全事件的主要场景? (3)什么是用于规划和选择信息安全控制的决策过程?目前在技术进步的发展趋势提出了新的安全要求信息系统。这是所有应用领域,包括军事,尤其是关于其不可避免的联系网络空间如此。然而,大多数的这些信息系统在适应不同的环境规则中指定的时间,可能会导致什么意外和危险的安全流动。这项研究旨在评估的葡萄牙陆军限制军事学说或如何促进国际标准ISO / IEC 27001(信息系统安全管理)的实施,并同时提出了选择和信息安全控制管理形式化方法,基于在该标准,并与军事组织排列。本案例研究由三个阶段组成:第一阶段包括收集和组织的重要文件的分析;在第二阶段,调查问卷在军事组织应用,以三个不同的群体 - 决策者,信息安全专家,并与特别与信息的使用功能的员工;最后,在第三阶段中,用专家采访用于验证从其它相所获得的结果。这项研究揭示了军事组织内的(1)信息安全是建立物质和人力的攻击向量的基础上,针对基础设施支持的信息在组织(即信息系统)(2)流,信息安全在军事组织施加的控制都包含在ISO 27001; (3)规划和应用的信息安全控制的选择是由决策者和信息安全专家提出,旨在保护数字信息诚信为主。看来,专家从类比强加其规划方案基本推断知识(如以下准则),或者更确切地说,寻求选择和检索过去的成功的信息安全的情况下,即类似场景就在规划的情况以及可能(可能)导致选择和实现最有效的信息安全控制的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号