首页> 外文期刊>Information management & computer security >Reaching escape velocity $ A practiced approach to information security management system implementation
【24h】

Reaching escape velocity $ A practiced approach to information security management system implementation

机译:达到逃生速度$一种实施信息安全管理系统的实践方法

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Purpose - This paper aims to demonstrate and offer an open source toolkit with the intent that making technology available to the community may serve to support organizations planning an information security management system implementation. Design/methodology/approach - A case study is presented which highlights the authors' approach to building capability and subsequently overcoming inertial forces which would otherwise have impeded the organization's compliance initiative. Findings - The case study proposes a novel approach to managing an ISMS implementation through the use of a custom developed toolkit, which based on the experience of the authors enabled the subject organization to achieve ISO 27001 certification. Practical implications - The adoption of the approach and tradecraft presented in the paper may enable similar organizations in building capacity to better manage information security programs. Originality/value - Insomuch as the recently revised ISO 27001 Information Security Code of Practice is well documented, comprehensive, methodological and widely supported, it is evident from the relatively low volume of certifications (a list of current certification registrations may be found at the ISMS International User Group Certificate Register - www.iso27001certificates.com), that many compliance initiatives are challenged in realizing full success. Based on the experiences presented in this paper, the authors believe these challenges must be overcome with appropriate capability building necessary to achieve a successful implementation.
机译:目的-本文旨在演示并提供一个开放源代码工具箱,其意图是使向社区提供技术可以帮助支持组织计划信息安全管理系统的实施。设计/方法/方法-提出了一个案例研究,着重强调了作者的能力建设方法,随后克服了惯性力,否则惯性力会妨碍组织的遵从性。调查结果-案例研究提出了一种通过使用定制开发的工具包来管理ISMS实施的新颖方法,该方法基于作者的经验使主题组织能够获得ISO 27001认证。实际的意义-采用本文中介绍的方法和技术可以使类似的组织能够进行能力建设,以更好地管理信息安全计划。原创性/价值-由于最近修订的ISO 27001信息安全操作规范已得到充分记录,全面,方法论和广泛支持,因此从相对较低的认证量中可以明显看出(可以在ISMS上找到当前认证注册的列表)国际用户组证书注册-www.iso27001certificates.com),许多合规性计划在实现全面成功方面面临挑战。基于本文介绍的经验,作者认为必须通过适当的能力建设来克服这些挑战,以实现成功的实施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号