首页> 外文会议>European Conference on Information Warfare and Security >National Security Auditing Criteria, KATAKRI: Leading Auditor Training and Auditing Process
【24h】

National Security Auditing Criteria, KATAKRI: Leading Auditor Training and Auditing Process

机译:国家安全审计标准,卡塔克里:领先的审计培训和审计过程

获取原文

摘要

The National Security Auditing Criteria, KATAKRI, were published in 2009, revised in 2011, and version III is currently under revision. The root of KATAKRI is to preserve the confidentiality of any confidential and classified information held by the organisation concerned. One of KATAKRI's aims is to combine the actions of authorities when verifying the security level of a company or other corporation by carrying out security auditing. From the enterprise operators' point of view, the focus of security auditing is to eliminate unfair competition and maintain an equal opportunity field for operators. Another of KATAKRI's aims is to improve national security when Finnish Defence Forces or other security authorities apply subcontracting. KATAKRI is also intended to help companies and corporations when they are developing their own security level. The purpose of this case study is to find out: what is expected from the security auditing process and from the leading auditor; what kind of competence the auditor should have; and how the security auditing training and qualification should be developed to correspond with the needs of the security field. The empirical research was conducted in the form of interviews, questionnaires and observations made as a student during the first KATAKRI leading auditor course executed 2/2/2012-12/12/2012. The combined results showed that deep knowledge of the security field and competence to manage overall security is required from security auditors. Furthermore, it was concluded that qualifications for security auditors should be created in accordance with ISO Standard 19011:2011, which provides a very strong competence model. In light of the above, it is recommended that the academic level, content and requirements of future audit and security auditing training should be clearly defined, and the quality of the training should be standardised and certified. The results also indicate that KATAKRI version II still has defects due to its inconsistency. One task of auditing processes should be collecting information about KATAKRI's shortcomings, and they should be systematically analysed. Future leading auditor courses would be suitable scenes to analyse shortcomings and to propose improvements to KATAKRI. KATAKRI should be revised every second or third year.
机译:国家安全审计标准,卡塔克里于2009年发表于2009年,于2011年修订,第三次版本目前正在修订。卡特卡里的根源是保留有关组织所持的任何机密和分类信息的机密性。卡塔克里的目标之一是通过进行安全审计,将当局或其他公司的安全级别结合起来。从企业运营商的观点来看,安全审计的重点是消除不公平的竞争,维持运营商的平等机会领域。当芬兰国防部队或其他安全机构适用分包时,另一位卡特卡里的目标是提高国家安全。卡塔克里还旨在帮助公司和公司在发展自己的安全水平时。本案例研究的目的是找出:从安全审计过程和领先的审计师来看,预期的内容是什么;审计员应该有什么样的能力;以及如何制定安全审计培训和资格,以与安全领域的需求相对应。经验研究是以访谈,问卷和作为学生的观察的形式进行的,在第一个卡塔克里领先的审计课程中执行2/2 / 2012-12 / 12/12 / 2012。组合结果表明,安全审计员需要深入了解安全领域和管理整体安全性的能力。此外,它的结论是,安全审计师的资格应根据ISO标准19011:2011创建,提供了一个非常强大的能力模型。鉴于上述情况,建议明确定义未来审计和安全审计培训的学术水平,内容和要求,应标准化和认证培训质量。结果还表明,由于其不一致而仍然存在缺陷。审计流程的一项任务应收集有关Katakri的缺点的信息,并应系统地分析。未来的领先审计课程将是适当的场景,分析缺点并提出改善卡塔克里。卡塔克里应每秒或三年修订。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号