A process framework for information security management

被引:15
|
作者
Haufe, Knut [1 ]
Colomo-Palacios, Ricardo [2 ]
Dzombeta, Srdan [3 ]
Brandis, Knud [3 ]
Stantchev, Vladimir [4 ]
机构
[1] Persicon Corp, Informat Secur Management Syst, Friedrichstr 100, D-10117 Berlin, Germany
[2] Ostfold Univ Coll, Dept Comp Sci, BRA Veien 4, N-178 Halden, Norway
[3] Persicon Corp, Friedrichstr 100, D-10117 Berlin, Germany
[4] SRH Hsch Berlin, Ernst Reuter Pl 10, D-10587 Berlin, Germany
关键词
information security; IT security management; ISMS; process framework;
D O I
10.12821/ijispm040402
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
Securing sensitive organizational data has become increasingly vital to organizations. An Information Security Management System (ISMS) is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security. Key elements of the operation of an ISMS are ISMS processes. However, and in spite of its importance, an ISMS process framework with a description of ISMS processes and their interaction as well as the interaction with other management processes is not available in the literature. Cost benefit analysis of information security investments regarding single measures protecting information and ISMS processes are not in the focus of current research, mostly focused on economics. This article aims to fill this research gap by proposing such an ISMS process framework as the main contribution. It is based on a set of agreed upon ISMS processes in existing standards like ISO 27000 series, COBIT and ITIL. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the ISMS, instead of focusing on measures and controls. By this, as a main finding, the systemic character of the ISMS consisting of processes and the perception of relevant roles of the ISMS is strengthened.
引用
收藏
页码:27 / 47
页数:21
相关论文
共 50 条
  • [1] A FRAMEWORK FOR INFORMATION SECURITY MANAGEMENT
    Angheluta, Dragos-Ionut
    Lupu, Luminita-Mihaela
    [J]. FROM MANAGEMENT OF CRISIS TO MANAGEMENT IN A TIME OF CRISIS, 2016, : 2 - 16
  • [2] A framework for the management of information security
    Leiwo, J
    Zheng, YL
    [J]. INFORMATION SECURITY, 1998, 1396 : 232 - 245
  • [3] Analytical Hierarchy Process Approach for the Metrics of Information Security Management Framework
    Moeti, Michael
    Kalema, Billy Mathias
    [J]. 2014 SIXTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, COMMUNICATION SYSTEMS AND NETWORKS (CICSYN), 2014, : 89 - 94
  • [4] A conceptual framework for information security management
    Finne, T
    [J]. COMPUTERS & SECURITY, 1998, 17 (04) : 303 - 307
  • [5] A framework for the management of information security risks
    Jones, A.
    [J]. BT TECHNOLOGY JOURNAL, 2007, 25 (01) : 30 - 36
  • [6] An Integrated Framework for Information Security Management
    Ma, Qingxiong
    Schmidt, Mark B.
    Pearson, J. Michael
    [J]. REVIEW OF BUSINESS, 2009, 30 (01): : 58 - 69
  • [7] A Framework for Information Security Governance and Management
    Carcary, Marian
    Renaud, Karen
    McLaughlin, Stephen
    O'Brien, Conor
    [J]. IT PROFESSIONAL, 2016, 18 (02) : 22 - 30
  • [8] Information Security in Supply Chains - A Process Framework
    Roy, Arup
    Gupta, A. D.
    Deshmukh, S. G.
    [J]. 2012 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEM), 2012, : 1448 - 1452
  • [9] The Automating Process of Information Security Management
    Sokolov, Sergey S.
    Alimov, Oleg M.
    Golubeva, Mariy G.
    Burlov, Vyacheslav G.
    Vikhrov, Nikolai M.
    [J]. PROCEEDINGS OF THE 2018 IEEE CONFERENCE OF RUSSIAN YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING (EICONRUS), 2018, : 124 - 127
  • [10] A PROCESS APPROACH TO INFORMATION SECURITY MANAGEMENT
    VONSOLMS, R
    VONSOLMS, SH
    CARROLL, JM
    [J]. COMPUTER SECURITY, 1993, 37 : 385 - 399