Towards Automation in Information Security Management Systems

被引:10
|
作者
Brunner, Michael [1 ]
Sillaber, Christian [1 ]
Breu, Ruth [1 ]
机构
[1] Univ Innsbruck, Inst Comp Sci, Innsbruck, Austria
关键词
Security Requirements; Information Security Management System; Information Security Risk Management; Process Automation;
D O I
10.1109/QRS.2017.26
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Establishing and operating an Information Security Management System (ISMS) to protect information values and information systems is in itself a challenge for larger enterprises and small and medium sized businesses alike. A high level of automation is required to reduce operational efforts to an acceptable level when implementing an ISMS. In this paper we present the ADAMANT framework to increase automation in information security management as a whole by establishing a continuous risk-driven and context-aware ISMS that not only automates security controls but considers all highly interconnected information security management tasks. We further illustrate how ADAMANT is suited to establish an ISO 27001 compliant ISMS for small and medium-sized enterprises and how not only the monitoring of security controls but a majority of ISMS related activities can be supported through automated process execution and workflow enactment.
引用
收藏
页码:160 / 167
页数:8
相关论文
共 50 条
  • [1] Information security management in industrial automation systems
    Savola, Reijo
    [J]. 2006 IEEE International Conference on Industrial Technology, Vols 1-6, 2006, : 2116 - 2121
  • [2] Towards Automation of Privacy and Security Risks Analysis in Identity Management Systems
    Paintsil, Ebenezer
    [J]. 2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 720 - 727
  • [3] Towards Autonomic Security Management of Healthcare Information Systems
    Chen, Qian
    Lambright, Jonathan
    Abdelwahed, Sherif
    [J]. 2016 IEEE FIRST INTERNATIONAL CONFERENCE ON CONNECTED HEALTH: APPLICATIONS, SYSTEMS AND ENGINEERING TECHNOLOGIES (CHASE), 2016, : 113 - 118
  • [4] SCMM-tool - Tool for computer automation of the information security management systems
    Sanchez, Luis Enrique
    Villafranca, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    [J]. ICSOFT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL SE: SOFTWARE ENGINEERING, 2007, : 311 - +
  • [5] Improving the Automation of Security Information Management: A Collaborative Approach
    Aguirre, Idoia
    Alonso, Sergio
    [J]. IEEE SECURITY & PRIVACY, 2012, 10 (01) : 55 - 59
  • [6] Security automation: The degree of information security in automated systems for process industry
    Kruschitz, Erwin
    [J]. AUTOMATION 2009, 2009, 2067 : 301 - 304
  • [7] INFORMATION-SYSTEMS SECURITY AND FRAUD PREVENTION IN OFFICE AUTOMATION SYSTEMS
    STANLEY, PM
    [J]. COMPUTER SECURITY, 1993, 37 : 375 - 383
  • [8] Information systems security metrics management
    Kovacich, G
    [J]. COMPUTERS & SECURITY, 1997, 16 (07) : 610 - 618
  • [9] Security management: An information systems setting
    Warren, MJ
    Batten, LM
    [J]. INFORMATION SECURITY AND PRIVACY, 2002, 2384 : 257 - 270
  • [10] Security management for radiological information systems
    Caramella, D
    Braccini, G
    Fabbrini, F
    Montanari, S
    Neri, E
    [J]. CAR '97 - COMPUTER ASSISTED RADIOLOGY AND SURGERY, 1997, 1134 : 1011 - 1011