首页> 外文期刊>International journal of technology diffusion >Investigation into the State-of-Practice of Operations Security Management Based on ISO/IEC 27002
【24h】

Investigation into the State-of-Practice of Operations Security Management Based on ISO/IEC 27002

机译:基于ISO / IEC 27002的运营安全管理实践状况调查

获取原文
获取原文并翻译 | 示例
           

摘要

This study assessed information security management in organizations through a questionnaire based on the ISO/IEC 27002, with special focus on operations security. A survey with cross-sectional research design was conducted and data collected from 223 participants from 56 organizations. Overall, the level of operations security maturity was 61.2%, which is the maturity Level 3 (well-defined). This level suggested that operations security controls and processes were documented, approved, and implemented organization-wide. Backups and malware protection were the most implemented security controls, while logging, auditing and monitoring were the least implemented controls. Assessment of inter-organizational operations security found significant differences among the organizations. Financial and Health Care Institutions outperform Educational Institutions and Government Public Service. The study provided insight into maturity levels of operations security controls and the results useful for benchmarking inter-organizational performance, competitiveness and improvement in information security.
机译:这项研究通过基于ISO / IEC 27002的调查表评估了组织中的信息安全管理,特别关注运营安全性。进行了一项具有横断面研究设计的调查,并收集了来自56个组织的223名参与者的数据。总体而言,运营安全成熟度级别为61.2%,这是成熟度级别3(定义明确)。此级别建议在组织范围内记录,批准和实施操作安全控制和流程。备份和恶意软件防护是实施最多的安全控制,而日志记录,审计和监视是实施最少的控制。组织间运营安全性评估发现组织之间存在显着差异。金融和保健机构的表现优于教育机构和政府公共服务。该研究提供了对运营安全控制成熟度的了解,并为基准化组织间绩效,竞争力和信息安全改进提供了有益的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号