A process framework for information security management

被引:15
|
作者
Haufe, Knut [1 ]
Colomo-Palacios, Ricardo [2 ]
Dzombeta, Srdan [3 ]
Brandis, Knud [3 ]
Stantchev, Vladimir [4 ]
机构
[1] Persicon Corp, Informat Secur Management Syst, Friedrichstr 100, D-10117 Berlin, Germany
[2] Ostfold Univ Coll, Dept Comp Sci, BRA Veien 4, N-178 Halden, Norway
[3] Persicon Corp, Friedrichstr 100, D-10117 Berlin, Germany
[4] SRH Hsch Berlin, Ernst Reuter Pl 10, D-10587 Berlin, Germany
关键词
information security; IT security management; ISMS; process framework;
D O I
10.12821/ijispm040402
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
Securing sensitive organizational data has become increasingly vital to organizations. An Information Security Management System (ISMS) is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security. Key elements of the operation of an ISMS are ISMS processes. However, and in spite of its importance, an ISMS process framework with a description of ISMS processes and their interaction as well as the interaction with other management processes is not available in the literature. Cost benefit analysis of information security investments regarding single measures protecting information and ISMS processes are not in the focus of current research, mostly focused on economics. This article aims to fill this research gap by proposing such an ISMS process framework as the main contribution. It is based on a set of agreed upon ISMS processes in existing standards like ISO 27000 series, COBIT and ITIL. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the ISMS, instead of focusing on measures and controls. By this, as a main finding, the systemic character of the ISMS consisting of processes and the perception of relevant roles of the ISMS is strengthened.
引用
收藏
页码:27 / 47
页数:21
相关论文
共 50 条
  • [31] A security management information model derivation framework:: From goals to configurations
    Laborde, R
    Barrère, F
    Benzekri, A
    [J]. FORMAL ASPECTS IN SECURITY AND TRUST, 2006, 3866 : 217 - 234
  • [32] Information security risks management framework - A step towards mitigating security risks in university network
    Joshi, Chanchala
    Singh, Umesh Kumar
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 35 : 128 - 137
  • [33] Alcatel information security framework
    Hayes, J
    [J]. ALCATEL TELECOMMUNICATIONS REVIEW, 2002, (04): : 273 - 279
  • [34] Security Framework for Information Systems
    Martins, Jose
    dos Santos, Henrique
    Nunes, Paulo
    [J]. PROCEEDINGS OF THE 8TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2009, : 164 - 176
  • [35] Information security governance framework
    Faculty of Informatics, Kogakuin University, Japan
    不详
    不详
    不详
    不详
    不详
    [J]. Proc ACM Conf Computer Commun Secur, (1-5):
  • [36] An information security governance framework
    Da Veiga, A.
    Eloff, J. H. P.
    [J]. INFORMATION SYSTEMS MANAGEMENT, 2007, 24 (04) : 361 - 372
  • [37] A FRAMEWORK FOR INFORMATION SECURITY EVALUATION
    VONSOLMS, R
    VANDEHAAR, H
    VONSOLMS, SH
    CAELLI, WJ
    [J]. INFORMATION & MANAGEMENT, 1994, 26 (03) : 143 - 153
  • [38] A framework for the governance of information security
    Posthumus, S
    von Solms, R
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 638 - 646
  • [39] A responsibility framework for information security
    Posthumus, S
    von Solms, R
    [J]. SECURITY MANAGEMENT, INTEGRITY, AND INTERNAL CONTROL IN INFORMATION SYSTEMS, 2005, 193 : 205 - 221
  • [40] A framework for ad hoc information management for the building design process
    Jacob, Jeevan
    Varghese, Koshy
    [J]. ENGINEERING CONSTRUCTION AND ARCHITECTURAL MANAGEMENT, 2018, 25 (08) : 1034 - 1052