A process framework for information security management

被引:15
|
作者
Haufe, Knut [1 ]
Colomo-Palacios, Ricardo [2 ]
Dzombeta, Srdan [3 ]
Brandis, Knud [3 ]
Stantchev, Vladimir [4 ]
机构
[1] Persicon Corp, Informat Secur Management Syst, Friedrichstr 100, D-10117 Berlin, Germany
[2] Ostfold Univ Coll, Dept Comp Sci, BRA Veien 4, N-178 Halden, Norway
[3] Persicon Corp, Friedrichstr 100, D-10117 Berlin, Germany
[4] SRH Hsch Berlin, Ernst Reuter Pl 10, D-10587 Berlin, Germany
关键词
information security; IT security management; ISMS; process framework;
D O I
10.12821/ijispm040402
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
Securing sensitive organizational data has become increasingly vital to organizations. An Information Security Management System (ISMS) is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security. Key elements of the operation of an ISMS are ISMS processes. However, and in spite of its importance, an ISMS process framework with a description of ISMS processes and their interaction as well as the interaction with other management processes is not available in the literature. Cost benefit analysis of information security investments regarding single measures protecting information and ISMS processes are not in the focus of current research, mostly focused on economics. This article aims to fill this research gap by proposing such an ISMS process framework as the main contribution. It is based on a set of agreed upon ISMS processes in existing standards like ISO 27000 series, COBIT and ITIL. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the ISMS, instead of focusing on measures and controls. By this, as a main finding, the systemic character of the ISMS consisting of processes and the perception of relevant roles of the ISMS is strengthened.
引用
收藏
页码:27 / 47
页数:21
相关论文
共 50 条
  • [21] An Information Security Management Approach for an Electoral Process in Ecuador
    Toapanta Toapanta, Segundo Moises
    Valero Carrillo, Andrea Paola
    Naranjo Sanchez, Bertha Alice
    Mafia Gallegos, Luis Enrique
    [J]. FUZZY SYSTEMS AND DATA MINING V (FSDM 2019), 2019, 320 : 921 - 932
  • [22] A meta-process for information security risk management
    Papadaki, Katerina
    Polemi, Nineta
    Damilos, Dimitrios Konnos
    [J]. GLOBAL E-SECURITY, PROCEEDINGS, 2008, 12 : 257 - +
  • [23] A meta-process for information security risk management
    Papadaki, Katerina
    Polemi, Despina
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2008, 1 (04) : 336 - 343
  • [24] An Intelligent Agent-Based Framework for Information Security Management
    Jiang, Chengzhi
    Zhang, Bo
    Yu, Yong
    Zhang, Xiaojian
    [J]. INSTRUMENTATION, MEASUREMENT, CIRCUITS AND SYSTEMS, 2012, 127 : 807 - 814
  • [25] Framework to implement information security management systems: An asset to project management processes
    Mena, Alvaro
    [J]. 2018 37TH INTERNATIONAL CONFERENCE OF THE CHILEAN COMPUTER SCIENCE SOCIETY (SCCC), 2018,
  • [26] A Risk Management Process for Consumers: The Next Step in Information Security
    van Cleeff, Andre
    [J]. NEW SECURITY PARADIGMS WORKSHOP 2010, 2010, : 107 - 114
  • [27] Designing a Process Reference Model for Information Security Management Systems
    Mangin, Olivier
    Barafort, Beatrix
    Heymans, Patrick
    Dubois, Eric
    [J]. SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION, 2012, 290 : 129 - +
  • [28] INFORMATION SECURITY MANAGEMENT FRAMEWORK SUITABILITY ESTIMATION FOR SMALL AND MEDIUM ENTERPRISE
    Kauspadiene, Laima
    Ramanauskaite, Simona
    Cenys, Antanas
    [J]. TECHNOLOGICAL AND ECONOMIC DEVELOPMENT OF ECONOMY, 2019, 25 (05) : 979 - 997
  • [29] Corroborative Intersection of the Information Security Standards and the Legal Framework on Data Management
    Zulhuda, Sonny
    [J]. SECOND INTERNATIONAL CONFERENCE ON COMPUTER AND ELECTRICAL ENGINEERING, VOL 1, PROCEEDINGS, 2009, : 200 - 203
  • [30] Balancing performance measures for information security management - A balanced scorecard framework
    Huang, Shi-Ming
    Lee, Chia-Ling
    Kao, Ai-Chin
    [J]. INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2006, 106 (1-2) : 242 - 255