首页> 外文会议>Proceedings of the eleventh Americas conference on information systems (AMCIS 2005) >Navigating the Information Security Landscape:Mapping the Relationship betweenISO 15408:1999 and ISO 17799:2000
【24h】

Navigating the Information Security Landscape:Mapping the Relationship betweenISO 15408:1999 and ISO 17799:2000

机译:导航信息安全领域:映射ISO 15408:1999和ISO 17799:2000之间的关系

获取原文
获取原文并翻译 | 示例

摘要

It is crucial for corporations operating in a multinational economy to have a seamless understanding of the security process.rnFor information assurance, ISO 15408:1999 (I.e. Common Criteria) and ISO 17799:2000 are the key standards, both of whichrnare needed for implementing a global approach to security. They provide a definition of the necessary elements of thernprocess as well as the basis for authoritative certification. However, the standards are entirely different in focus. The formerrnis product-oriented while the latter is strategic and organizational. That divergence is an obstacle to creating securernenterprises and it causes disagreement about the meaning and value of the certifications. Mapping the relationship betweenrnISO 15408 and ISO 17799 demonstrates their strengths and weaknesses and encourages organizations to use these standardsrneffectively. The results of our study indicate that while there are overlaps between these two standards, there are alsornsignificant gaps.
机译:对于在跨国经济中运作的公司来说,无缝地了解安全过程是至关重要的。对于信息保证,ISO 15408:1999(即通用标准)和ISO 17799:2000是关键标准,这两个标准都是实施安全管理所必需的。全球安全方法。它们提供了对流程必要元素的定义,以及权威认证的基础。但是,这些标准的重点完全不同。前者以产品为导向,而后者则是战略性和组织性的。这种差异是创建安全企业的障碍,并导致对证书含义和价值的分歧。绘制ISO 15408和ISO 17799之间的关系可以证明它们的优缺点,并鼓励组织有效地使用这些标准。我们的研究结果表明,尽管这两个标准之间存在重叠,但也存在巨大差距。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号