Auditing Information Security Management Systems – Towards a Practical Method
نویسنده
چکیده
This paper describes a research project related to the Swedish pilot certification scheme for information security management systems, based on the British Standard BS7799. Empirical data is gathered from several organisations seeking certification according to SS627799, which is a Swedish translation of BS7799. The project is focused on problems related to the assessment of information security controls. A software prototype for gapanalysis was developed, and refined through input from information security experts and software developers. The result is a tool called SBA Check 3.0, which is marketed by the Swedish Computer Society. In this doctoral research project, the tool is put forward as a tentative hypothesis, and it is contrasted with solutions and problems identified in the literature as well as from the studied organisations. This first paper presents the overall research problem and design.
منابع مشابه
Practical implementation of an ISO 17799- compliant information security management system using a novel ASD method
This paper discusses the practical implementation of the Agile Security Development (ASD framework and presents a case study that reviews the process of building an information security management system utilizing the framework. The case study reveals the action steps for a small and medium-sized organization to utilize the method. The ASD framework and its output is fully ISO/IEC17799 complian...
متن کاملTowards Measuring the Project Management Process During Large Scale Software System Implementation Phase
Project management is an important factor to accomplish the decision to implement large-scale software systems (LSS) in a successful manner. The effective project management comes into play to plan, coordinate and control such a complex project. Project management factor has been argued as one of the important Critical Success Factor (CSF), which need to be measured and monitored carefully duri...
متن کاملCritical Assessment of Auditing Contributions to Effective and Efficient Security in Database Systems
Database auditing has become a very crucial aspect of security as organisations increase their adoption of database management systems (DBMS) as major asset that keeps, maintain and monitor sensitive information. Database auditing is the group of activities involved in observing a set of stored data in order to be aware of the actions of users. The work presented here outlines the main auditing...
متن کاملInformation Security Behavioral Model: Towards Employees’ Knowledge and Attitude
Information Security has become a significant concern for today’s organizations. The internal security threats acts as the most curtail type of security threat within an organization. These internal security threats are a result of poor conduct of security behavior by the employees within an organization. If not deal properly, it may hamper the auditing of organization. Auditing plays an import...
متن کاملامنیت اطلاعات سامانه های تحت وب نهاد کتابخانه های عمومی کشور
Purpose: This paper aims to evaluate the security of web-based information systems of Iran Public Libraries Foundation (IPLF). Methodology: Survey method was used as a method for implementation. The tool for data collection was a questionnaire, based on the standard ISO/IEC 27002, that has the eleven indicators and 79 sub-criteria, which examines security of web-based information systems of IP...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2001