...
首页> 外文期刊>Computer and Information Science >Presenting a Model for Ranking Organizations Based on the Level of the Information Security Maturity
【24h】

Presenting a Model for Ranking Organizations Based on the Level of the Information Security Maturity

机译:提出基于信息安全成熟度等级的组织排名模型

获取原文
           

摘要

Undoubtedly, in today’s new business information has donated the most competitive advantage for the organizations. Although just collecting, processing and retrieving of data were significant in the past, the subject of information security is turned into a serious challenge in micro and macro levels of organizational management. Indeed, observance of the information security principals is counted as a critical infrastructure in today’s knowledge based organizations. In order to realize this purpose, we need to make a strategic plan for IT security. However, we cannot expect to design a comprehensive plan, if we don’t have accurate statistics about the level of the information security maturity in current organizations. The goal of this paper is ranking organizations about the level of the information security maturity by presenting a model based on the knowledge of multi criteria decision making. So, first of all, in the literature review, the models and different standards presented in the information security maturity were studied. After determining information security criteria in technical and managerial forms, considering the triple criteria of security, safety and stability, weight devoting was performed by using the expert’s views in the IT departments of three chosen organizations A, B and C. Ultimately, ranking of these organizations based on the level of information security maturity was done by applying the algorithm of PROMETHEE II. In the final step there was a comparison between the result of this model and two other security maturity models. The same results show reliability and validity of proposed ranking model.
机译:毫无疑问,在当今的新业务信息中,这为组织带来了最大的竞争优势。尽管过去仅收集,处理和检索数据非常重要,但是信息安全性的主题已变成组织管理的微观和宏观层面的严峻挑战。实际上,在当今基于知识的组织中,遵守信息安全原则被视为至关重要的基础架构。为了实现此目的,我们需要制定IT安全的战略计划。但是,如果我们没有关于当前组织中信息安全成熟度水平的准确统计信息,我们就不能期望制定一个全面的计划。本文的目的是通过提出基于多准则决策知识的模型,对组织的信息安全成熟度等级进行排名。因此,首先,在文献综述中,研究了信息安全成熟度中提出的模型和不同标准。在确定了技术和管理形式的信息安全标准之后,考虑了安全性,安全性和稳定性的三重标准,通过使用三个选定的组织A,B和C的IT部门的专家意见来进行重量分配。最终,对这些组织进行排名应用PROMETHEE II算法,可以基于信息安全成熟度级别组织组织。在最后一步中,此模型的结果与其他两个安全性成熟度模型进行了比较。同样的结果表明了所提出的排序模型的可靠性和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号