首页> 外文会议>IEEE International Conference on Cyber Security and Cloud Computing >A Framework for the Information Classification in ISO 27005 Standard
【24h】

A Framework for the Information Classification in ISO 27005 Standard

机译:ISO 27005标准中信息分类的框架

获取原文

摘要

Information Security Risk Management (ISRM) process involves several activities to conduct a risk management (RM) task in an organization. ISRM activities require access to various information related to the organization. An organization often needs to share information related to an ISRM process with the stakeholders involved in the activity. Therefore, it is important to manage the information which is critical to the operations of the organization. The presence of an information classification scheme can enable the proper handling of the information involved in the RM task. We selected ISO/IEC27005:2011 risk management standard to assess various information generated during the process of applying this standard in an organization. The purpose of this study is to propose a framework to show various information objects involved in ISO27005 risk management standard and classify the information based on the guideline provided by UNINETT scheme. A case scenario of a health clinic is developed to identify ISRM related information objects using the proposed framework and classify the information using UNINETT scheme.
机译:信息安全风险管理(ISRM)进程涉及在组织中进行风险管理(RM)任务的几项活动。 ISRM活动需要访问与本组织相关的各种信息。组织通常需要与参与活动的利益相关者共享与ISRM流程相关的信息。因此,管理对组织操作至关重要的信息非常重要。信息分类方案的存在可以可以正确处理RM任务中涉及的信息。我们选择了ISO / IEC27005:2011年风险管理标准,以评估在组织中应用本标准的过程中产生的各种信息。本研究的目的是提出一个框架,以显示ISO27005风险管理标准中涉及的各种信息对象,并根据UNINETT计划提供的指南对信息进行分类。开发了健康诊所的案例场景,以使用所提出的框架来识别ISRM相关信息对象,并使用Uninett方案对信息进行分类。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号