Today's Action is Better than Tomorrow's Cure - Evaluating Information Security at a Premier Indian Business School

被引:1
|
作者
Das, Saini [1 ]
Mukhopadhyay, Arunabha [1 ]
Bhasker, Bharat [1 ,2 ]
机构
[1] Indian Inst Management, Informat Technol & Syst Area, Lucknow, Uttar Pradesh, India
[2] Univ Maryland, Business Management Sch, Informat Syst, College Pk, MD 20742 USA
关键词
Confidentiality; Integrity and Availability (CIA) of Information; Information Security Management System (ISMS); Network Security Components Security Policy; Simple Mail Transfer Protocol (SMTP);
D O I
10.4018/jcit.2013070101
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information Security breaches today affect a large number of organizations including universities, globally. They pose an immense threat to the C-I-A (confidentiality, integrity and availability) of information. Hence, it is important to have proper Information Security Management System (ISMS) designed in accordance with industry adopted standards for risk management. The current case explores the IT infrastructure at a premier Indian business school where internet support is required round the clock. The entire ISMS framework of the organization, including security policy, security budget and network components, is described. Though the security infrastructure apparently seemed to be adequate, a spate of hacking attacks targeted at the SMTP server attempted to cripple the extremely crucial email services for the period of the attack by generating spam. The primary security challenges facing the organization including nature and appropriateness of ISMS, adequacy of the security policy, budget allocation for IT security, etc., are left open for discussion.
引用
收藏
页码:1 / 23
页数:23
相关论文
共 4 条