首页> 外文期刊>Journal of Information Security >An Innovative Soft Design Science Methodology for Improving Development of a Secure Information System in Tanzania Using Multi-Layered Approach
【24h】

An Innovative Soft Design Science Methodology for Improving Development of a Secure Information System in Tanzania Using Multi-Layered Approach

机译:一种创新的软设计科学方法,用于使用多层方法改善坦桑尼亚安全信息系统的发展

获取原文
       

摘要

This paper presents an innovative Soft Design Science Methodology for improving information systems security using multi-layered security approach. The study applied Soft Design Science Methodology to address the problematic situation on how information systems security can be improved. In addition, Soft Design Science Methodology was compounded with mixed research methodology. This holistic approach helped for research methodology triangulation. The study assessed security requirements and developed a framework for improving information systems security. The study carried out maturity level assessment to determine security status quo in the education sector in Tanzania. The study identified security requirements gap (IT security controls, IT security measures) using ISO/IEC 21827: Systems Security Engineering-Capability Maturity Model (SSE-CMM) with a rating scale of 0 - 5. The results of this study show that maturity level across security domain is 0.44 out of 5. The finding shows that the implementation of IT security controls and security measures for ensuring security goals are lacking or conducted in ad-hoc. Thus, for improving the security of information systems, organisations should implement security controls and security measures in each security domain (multi-layer security). This research provides a framework for enhancing information systems security during capturing, processing, storage and transmission of information. This research has several practical contributions. Firstly, it contributes to the body of knowledge of information systems security by providing a set of security requirements for ensuring information systems security. Secondly, it contributes empirical evidence on how information systems security can be improved. Thirdly, it contributes on the applicability of Soft Design Science Methodology on addressing the problematic situation in information systems security. The research findings can be used by decision makers and lawmakers to improve existing cyber security laws, and enact laws for data privacy and sharing of open data.
机译:本文介绍了一种创新的软设计科学方法,可以使用多层安全方法改进信息系统安全性。该研究应用软设计科学方法解决了如何提高信息系统安全性的问题情况。此外,软设计科学方法与混合研究方法复杂化。这种整体方法有助于研究方法三角测量。该研究评估了安全要求,并制定了一个改进信息系统安全性的框架。该研究进行了成熟程度评估,以确定坦桑尼亚教育部门的安全现状。该研究确定了使用ISO / IEC 21827的安全要求差距(IT安全控制,IT安全措施):系统安全工程 - 能力成熟度模型(SSE-CMM),评级为0-5。本研究的结果显示成熟度安全域中的级别为0.44,其中5分。该发现表明IT安全控制和确保安全目标的安全措施缺乏或在Ad-hoc中进行。因此,为了提高信息系统的安全性,组织应该在每个安全域(多层安全性)中实现安全控制和安全措施。本研究提供了一种用于在捕获,处理,存储和传输信息期间增强信息系统安全性的框架。这项研究有几种实际贡献。首先,它通过为确保信息系统安全性提供一组安全要求,有助于了解信息系统安全的知识。其次,它有助于如何提高信息系统安全性的经验证据。第三,它有助于软设计科学方法论对信息系统安全中有问题情况的适用性。决策者和立法者可以使用研究结果来改善现有的网络安全法,并制定数据隐私法律和公开数据的共享。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号