首页> 外文学位 >An approach to information system security assessment.
【24h】

An approach to information system security assessment.

机译:信息系统安全评估的一种方法。

获取原文
获取原文并翻译 | 示例

摘要

As the tremendous growth of networks and e-business changes the nature of traditional information security threats, the capability to provide prompt and accurate information to authorized users boosts the competitive power of an organization. In addition to the threats, organizations face complex requirements in complying with security and privacy regulations. These conditions force organizations to seek more robust information security systems. An effective information security program, requires periodic security assessments.; This study aims to develop an information security assessment model to evaluate the security level of an information security system. Based on respondents' comments, we choose higher education institutions as survey subjects. Utilizing literature reviews, information security standards, best practices, and information security assessment guides, we have formed the essential components of our information security assessment model. These components are organized as a two-layer structure---security controls and sub-security controls. In order to validate this model, we conducted two field studies and one web-survey. Based on the comments and number of responses, we chose higher education institutions as the survey subject for this study. The results of this study identify the different importance levels of security controls and sub-security controls. This model offers an improved security evaluation metric over extant methods. It also provides a potential baseline for the standard of information security metric. In this research, it does not only verify the varying importance levels of security controls and sub-security controls among different types of institutions but also in different sizes of organizations. This study also establishes a framework for information security assessment models for industries.
机译:随着网络和电子商务的迅猛发展改变了传统信息安全威胁的性质,向授权用户提供及时准确的信息的能力增强了组织的竞争能力。除了威胁之外,组织在遵守安全和隐私法规方面还面临着复杂的要求。这些条件迫使组织寻求更强大的信息安全系统。有效的信息安全计划需要定期的安全评估。本研究旨在开发一种信息安全评估模型,以评估信息安全系统的安全级别。根据受访者的意见,我们选择高等教育机构作为调查对象。利用文献综述,信息安全标准,最佳实践和信息安全评估指南,我们已经形成了信息安全评估模型的基本组成部分。这些组件被组织为两层结构-安全控制和子安全控制。为了验证该模型,我们进行了两次现场研究和一次网络调查。根据评论和回应数量,我们选择了高等教育机构作为本研究的调查对象。这项研究的结果确定了安全控制和子安全控制的不同重要性级别。该模型提供了优于现有方法的改进的安全评估指标。它还为信息安全度量标准提供了潜在的基准。在这项研究中,它不仅验证了不同类型的机构之间,而且在不同规模的组织中安全控制和子安全控制的不同重要性级别。这项研究还为行业信息安全评估模型建立了框架。

著录项

  • 作者

    Chao, Shu-chuan.;

  • 作者单位

    Cleveland State University.;

  • 授予单位 Cleveland State University.;
  • 学科 Computer Science.
  • 学位 D.B.A.
  • 年度 2005
  • 页码 159 p.
  • 总页数 159
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

  • 入库时间 2022-08-17 11:41:26

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号