ISMS Planning Based On ISO/IEC 27001:2013 Using Analytical Hierarchy Process at Gap Analysis Phase (Case Study : XYZ Institute)

被引:0
|
作者
Briliyant, Obrina Candra [1 ]
Candra, Johanes Widhi [1 ]
Tamba, Sion Rebeca [1 ]
机构
[1] Natl Crypto Inst, Bogor, Indonesia
来源
2017 11TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATION SYSTEMS SERVICES AND APPLICATIONS (TSSA) | 2017年
关键词
ISO/IEC 27001:2013; AHP; gap analysis;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The biggest challenge in information security planning is how to acquire precision in the gap analysis phase. According to the information security management system (ISMS) implementation guide based on ISO/IEC 27001:2013, the planning of ISMS has 5 stages. The 5 stages are : defining the range, perform gap analysis, accomplish risk assessment, determine the control and target, and determine the policy and procedure of ISMS. The gap analysis stage is required to assess the organization's current position toward ISMS implementation. This research suggested the use of AHP to determine which information security control that most relate to the organization needs and goals. We will conduct the process in one of Indonesia's organization called the XYZ institute. The result of this research is prioritization of information security gap handling that will be useful for XYZ institute to support their processes of ISO/IEC 27001:2013 implementation.
引用
收藏
页数:6
相关论文
共 23 条
  • [1] Information security failures identified and measured - ISO/IEC 27001:2013 controls ranked based on GDPR penalty case analysis
    Suorsa, M.
    Helo, P.
    INFORMATION SECURITY JOURNAL, 2024, 33 (03): : 285 - 306
  • [2] Designing Information Security Governance Recommendations and Roadmap Using COBIT 2019 Framework and ISO 27001:2013 (Case Study Ditreskrimsus Polda XYZ)
    Yasin, Muhammad
    Arman, Arry Akhmad
    Edward, Ian Joseph M.
    Shalannanda, Wervyan
    PROCEEDING OF 14TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATION SYSTEMS, SERVICES, AND APPLICATIONS (TSSA), 2020,
  • [3] Information security failures identified and measured - ISO/IEC 27001:2013 controls ranked based on GDPR penalty case analysis (vol Oct, 10.1080/19393555.2023.2270984, 2023)
    Suorsa, M.
    Helo, P.
    INFORMATION SECURITY JOURNAL, 2024, 33 (04): : 454 - 454
  • [4] Flood risk analysis using gis-based analytical hierarchy process: a case study of Bitlis Province
    Mehmet Cihan Aydin
    Elif Sevgi Birincioğlu
    Applied Water Science, 2022, 12
  • [5] Flood risk analysis using gis-based analytical hierarchy process: a case study of Bitlis Province
    Aydin, Mehmet Cihan
    Birincioglu, Elif Sevgi
    APPLIED WATER SCIENCE, 2022, 12 (06)
  • [6] GIS-Based Biomass Energy Sustainability Analysis Using Analytical Hierarchy Process: A Case Study in Medellin, Cebu
    Galang, Wenyville Nabor
    Tabanag, Ian Dominic
    Loretero, Michael
    INTERNATIONAL JOURNAL OF RENEWABLE ENERGY DEVELOPMENT-IJRED, 2021, 10 (03): : 551 - 561
  • [7] A Multi-case Study Analysis of Software Process Improvement in Very Small Companies Using ISO/IEC 29110
    Laporte, Claude Y.
    O'Connor, Rory V.
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2016, 2016, 633 : 30 - 44
  • [8] Web-based process planning system concept selection using Weighted Decision Matrix and Analytical Hierarchy Process: A case study of sheet metal bending operations
    Eriyeti, Murena
    Mpofu, Khumbulani
    Makinde, Olasumbo
    Trimble, John
    Wang, Xi
    SUSTAINABLE MANUFACTURING FOR GLOBAL CIRCULAR ECONOMY, 2019, 33 : 462 - 469
  • [9] Designing Recommendations and Road Map of Governance for Quality Management System of Online SKCK Based on Information Security Using ISO 9001: 2015 and ISO 27001: 2013 (Case Study: Ditintelkam Polda ABC)
    Putra, Prima Pringgo
    Arman, Arry Akhmad
    Edward, Ian Joseph Matheus
    Shalannanda, Wervyan
    PROCEEDING OF 14TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATION SYSTEMS, SERVICES, AND APPLICATIONS (TSSA), 2020,
  • [10] GIS-based landslide susceptibility mapping using analytical hierarchy process: a case study of Astore region, Pakistan
    Afzal, Nouman
    Ahmad, Adeel
    Shirazi, Safdar Ali
    Younes, Isma
    Le Thi Thu Ha
    EQA-INTERNATIONAL JOURNAL OF ENVIRONMENTAL QUALITY, 2022, 48 : 27 - 40