首页> 外文期刊>IAENG Internaitonal journal of computer science >A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard
【24h】

A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard

机译:基于NTC-ISO / IEC 27001标准的信息安全管理系统模型

获取原文
获取原文并翻译 | 示例
           

摘要

In an era of globalization, in which technology has allowed the development of companies to be promoted, data and information become essential assets in organizations, which are exposed to hackers, computer viruses, cyber espionage, and infrastructure failures are some of the problems organizations face daily. In this work, we aim to present a model of an information security management system, aligned with the NTC-ISO/IEC 27001:2013 standard, which applies to any organization and allows them to know their current status regarding the information security. Also, the proposed model will enable organizations to implement systemically and adequately controls, procedures, and policies required to preserve the integrity, confidentiality, and integrity of information assets. The model has been applied to an organization that provides technical information management and administration services in the hydrocarbon sector. The results of using the model in this organization, allowed to define its security structure, information security policies, and resources required to certify its management system. Additionally, information assets, technical vulnerabilities, and risks applied to all processes were identified.
机译:在全球化的时代,其中技术允许推广公司的发展,数据和信息成为组织的基本资产,这些组织受到黑客,计算机病毒,网络间谍和基础设施故障是组织面临的一些问题日常的。在这项工作中,我们的目标是介绍信息安全管理系统的模型,与NTC-ISO / IEC 27001:2013标准对齐,该标准适用于任何组织,并允许他们知道信息安全性的当前状态。此外,拟议的模型将使组织能够全身和充分控制,程序和策略来维护信息资产的完整性,机密性和完整性所需的策略。该模型已应用于提供碳氢化合物部门的技术信息管理和管理服务的组织。使用本组织中的模型的结果允许定义证明其管理系统所需的安全结构,信息安全策略和资源。此外,还确定了应用于所有流程的信息资产,技术漏洞和风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号