首页> 外文期刊>Information & Management >Information security management standards: Problems and solutions
【24h】

Information security management standards: Problems and solutions

机译:信息安全管理标准:问题与解决方案

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

International information security management guidelines play a key role in managing and certifying organizational IS. We analyzed BS7799, BS ISO/IEC17799: 2000, GASPP/GAISP, and the SSE-CMM to determine and compare how these guidelines are validated, and how widely they can be applied. First we found that BS7799, BS IS0/IEC17799: 2000, GASPP/GAISP and the SSE-CMM were generic or universal in scope; consequently they do not pay enough attention to the differences between organizations and the fact that their security requirements are different. Second, we noted that these guidelines were validated by appeal to common practice and authority and that this was not a sound basis for importanl international information security guidelines. To address these shortcomings, we believe that information security management guidelines should be seen as a library of material on information security management for practitioners.
机译:国际信息安全管理指南在组织IS的管理和认证中起着关键作用。我们分析了BS7799,BS ISO / IEC17799:2000,GASPP / GAISP和SSE-CMM,以确定并比较如何验证这些准则以及其适用范围。首先,我们发现BS7799,BS IS0 / IEC17799:2000,GASPP / GAISP和SSE-CMM在范围上是通用或通用的。因此,他们对组织之间的差异以及他们的安全要求不同的事实没有给予足够的重视。第二,我们注意到,这些准则已经通过呼吁通用惯例和权威得到验证,而这并不是重要的国际信息安全准则的可靠基础。为了解决这些缺点,我们认为信息安全管理指南应被视为从业人员信息安全管理的资料库。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号