首页> 外文期刊>International Journal of African and Asian Studies >A Reformed Information Security Management System (R-ISMS)
【24h】

A Reformed Information Security Management System (R-ISMS)

机译:改革的信息安全管理系统(R-ISMS)

获取原文
       

摘要

An Information Security Management System (ISMS) specifies the instruments and methods that an administration/management level of an institution uses to comprehensibly manage the tasks and activities aimed at achieving information security. ISMS evolved as a systematic and structured approach to managing information following advances in IT infrastructure, services and applications so that they remain secure. While there are various implemented ISMS frameworks, researchers continually try to emphasize and increase human participation in ensuring information security. The aim of this research study is to develop an algorithm-based model to facilitate effective ISMS services for organizations. This algorithm-based ISMS model employed Information Technology General Controls (ITGC) technique as an expansion of the vistas of known ISMS frameworks, to improve information security control in organizations. The purpose of refinement is to make the frameworks more easily understood, implemented, and measured in organizations by stakeholders.Microsoft Office Visio 2010 software was used in designing the reformed model. Bactracking and Branch-and-bound algorithms were used in developing the model. The model utilises the above named methods to address the problem of inadequate management systems for information security. The results of this study showed that, with the level of usability, International Organization for Standardization (ISO) standards are more easily implemented and well recognized by stakeholders (top management, staff, suppliers, customers/clients, regulators) unlike the other security frameworks. In conclusion, this study showed that R-ISMS is a customized algorithm model that assists organizations to enhance the ability in monitoring the performance of their activities, policies and procedures.
机译:信息安全管理系统(ISMS)指定了机构的管理/管理级别用来全面管理旨在实现信息安全的任务和活动的工具和方法。随着IT基础架构,服务和应用程序的发展,ISMS作为一种系统化和结构化的方法来管理信息,从而确保了它们的安全性。尽管存在各种已实施的ISMS框架,但研究人员不断尝试强调并增加人们在确保信息安全方面的参与。这项研究的目的是开发一种基于算法的模型,以促进组织的有效ISMS服务。这种基于算法的ISMS模型采用信息技术通用控制(ITGC)技术来扩展已知ISMS框架的远景,以改进组织中的信息安全控制。改进的目的是使利益相关者更容易理解,实施和衡量组织中的框架。MicrosoftOffice Visio 2010软件用于设计改革后的模型。 Bactracking和分支定界算法用于开发模型。该模型利用上述命名方法来解决信息安全管理系统不足的问题。这项研究的结果表明,与其他安全框架相比,在可用性方面,国际标准化组织(ISO)标准更易于实施并得到利益相关者(高层管理人员,员工,供应商,客户/客户,监管机构)的认可。总之,这项研究表明,R-ISMS是一个定制的算法模型,可以帮助组织增强监视其活动,政策和程序的绩效的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号