首页> 外文会议>CD-ARES 2013 >A Method for Re-using Existing ITIL Processes for Creating an ISO 27001 ISMS Process Applied to a High Availability Video Conferencing Cloud Scenario
【24h】

A Method for Re-using Existing ITIL Processes for Creating an ISO 27001 ISMS Process Applied to a High Availability Video Conferencing Cloud Scenario

机译:一种用于重新使用现有ITIL进程的方法,用于创建ISO 27001 ISMS进程应用于高可用性视频会议云场景

获取原文

摘要

Many companies have already adopted their business processes to be in accordance with defined and organized standards. Two standards that are sought after by companies are IT Infrastructure Library (ITIL) and ISO 27001. Often companies start certifying their business processes with ITIL and continue with ISO 27001. For small and medium-sized businesses, it is difficult to prepare and maintain the ISO 27001 certification. The IT departments of these companies often do not have the time to fully observere standards as part of their daily routine. ITIL and ISO 27001 perfectly fit into companies and help reduce errors through the standardization and comparability of products and services between themselves and other companies and partners. ISO 27001 specifically looks at security risks, countermeasures and remedial actions. We start with the processes that need to be in place for implementing ITIL in an organisation's business processes. We use a cloud service provider as a running example and compare ITIL processes with ISO 27001 processes. We identify which aspects of these two standards can be better executed. We propose a mapping between ITIL and ISO 27001 that makes them easier to understand and assists with the certification process. We show further how to prepare for audits as well as re-certification. Often, these two processes are seen separately and not in conjunction, where synergies can be exploited. Legal requirements, compliance and data security play an integral part in this process. In essence, we present checklists and guidelines for companies who want to prepare for standardization or that are already certified, but want to improve their business processes. We illustrate our method using an high availability video conferencing cloud example.
机译:许多公司已经通过了他们的业务流程,符合定义和有组织的标准。公司追捧的两个标准是IT基础设施图书馆(ITIL)和ISO 27001.经常公司开始使用ITIL认证其业务流程并继续使用ISO 27001.对于中小型企业,难以准备和维护ISO 27001认证。这些公司的IT部门往往没有时间将标准完全理解为日常生活的一部分。 ITIL和ISO 27001完全适合公司,并通过自己和其他公司与合作伙伴之间的产品和服务的标准化和可比性来帮助减少错误。 ISO 27001特别关注安全风险,对策和补救措施。我们首先在组织的业务流程中实现ITIL所需的过程。我们使用云服务提供商作为运行示例,并使用ISO 27001进程进行比较ITIL进程。我们确定这两个标准的哪些方面可以更好地执行。我们提出ITIL和ISO 27001之间的映射,使它们更容易理解和协助认证过程。我们进一步展示了如何准备审核以及重新认证。通常,这两个过程单独看,不结合,可以利用协同作用。法律要求,合规性和数据安全在此过程中播放一个组成部分。实质上,我们为想要为标准化做好准备或已经认证的公司提供清单和指南,而是想要改善其业务流程。我们使用高可用性视频会议云示例说明了我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号