首页> 外文期刊>International Journal of Cyber Warfare and Terrorism >Aligning Two Specifications for Controlling Information Security
【24h】

Aligning Two Specifications for Controlling Information Security

机译:统一两个规范以控制信息安全

获取原文
获取原文并翻译 | 示例
           

摘要

Assuring information security is a necessity in modern organizations. Many recommendations for information security management exist, which can be used to define a baseline of information security requirements. ISO/ IEC 27001 prescribes a process for an information security management system, and guidance to implement security controls is provided in ISO/IEC 27002. Finnish National Security Auditing Criteria (KATAKRI) has been developed by the national authorities in Finland as a tool to verify maturity of information security practices. KATAKRI defines both security control objectives and security controls to meet an objective. Here the authors compare and align these two specifications in the process, structural, and operational level, focusing on the security control objectives and the actual controls. Even if both specifications share the same topics on high level, the results reveal the differences in the scope and in the included security controls.
机译:在现代组织中,确保信息安全是必不可少的。存在许多有关信息安全管理的建议,这些建议可用于定义信息安全要求的基准。 ISO / IEC 27001规定了信息安全管理系统的过程,ISO / IEC 27002中提供了实施安全控制的指南。芬兰国家安全审核标准(KATAKRI)由芬兰国家主管部门制定,作为验证的工具信息安全实践的成熟度。 KATAKRI定义了安全控制目标和实现目标的安全控制。在这里,作者在安全,控制目标和实际控制上,在过程,结构和操作级别上比较和协调这两个规范。即使两个规范在高层上共享相同的主题,结果也显示出范围和所包含的安全控制方面的差异。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号