The design of information security management systems for small-to-medium size enterprises

被引:0
|
作者
Coles-Kemp, Elizabeth [1 ]
Overill, Richard [1 ]
机构
[1] Kings Coll London, London WC2R 2LS, England
关键词
information security management system; ISMS; small-to-medium size enterprise; SME;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Information security management systems (ISMSs) are often regarded as unnecessarily bureaucratic and for small-to-medium size enterprises (SMEs) they can be so bureaucratic that certification to information security management standard ISO 27001 becomes unrealistic. The bureaucracy arises largely as a result of misinterpretation of the standard and results from poor information security management process design and the use of inappropriate language in the risk assessment phase. ISO 27001 mandates the implementation of the following information security management processes: risk assessment, risk treatment, management review, internal audit, training and awareness, and incident management. However, in a SME these processes can be combined in a number of different ways to reduce the bureaucratic overhead and yet still construct an ISO 27001 compliant management system. The bureaucratic burden can be further reduced by tight implementation within the existing business processes. In particular, the bureaucracy of risk assessment can be reduced in two ways: by using linguistic metaphors appropriate for SMEs instead of the specialist language that is traditionally employed for information security risk assessment, and by combining risk assessment with a reflexive management review process. This paper presents a number of models for combining information security management processes and provides a number of case studies to show how these combined information security management processes can be implemented within standard business processes. The paper also offers a taxonomy of linguistic metaphors designed to be used in information security risk assessment in the SME.
引用
收藏
页码:47 / 54
页数:8
相关论文
共 50 条
  • [1] INFORMATION SECURITY MANAGEMENT IN SMALL AND MEDIUM ENTERPRISES
    Horovcak, Pavel
    Stehlikova, Beata
    [J]. 11TH INTERNATIONAL MULTIDISCIPLINARY SCIENTIFIC GEOCONFERENCE (SGEM 2011), VOL II, 2011, : 527 - 532
  • [2] Confederative ERP Systems for Small-to-Medium Enterprises
    Zemlicka, Michal
    Kral, Jaroslav
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2016, PT V, 2016, 9790 : 350 - 362
  • [3] MANAGEMENT ACCOUNTING INFORMATION USEFULNESS AND CLOUD COMPUTING QUALITIES AMONG SMALL-TO-MEDIUM ENTERPRISES
    Al Lami, Mohammed Fadil Farhan
    Maelah, Ruhanita
    Ghassan, Gheyath
    [J]. INTERNATIONAL JOURNAL OF MANAGEMENT STUDIES, 2019, 26 (01): : 1 - 31
  • [4] Information communication technology adoption by small-to-medium food enterprises
    Bhaskaran, Suku
    [J]. BRITISH FOOD JOURNAL, 2013, 115 (2-3): : 425 - 447
  • [5] Effect of financial management practices on the development of small-to-medium size forest enterprises: insight from Pakistan
    Muhammad Zada
    Cao Yukun
    Shagufta Zada
    [J]. GeoJournal, 2021, 86 : 1073 - 1088
  • [6] A Study on Information Security Management System Model for Small and Medium Enterprises
    Lee, Wan-Soo
    Jang, Sang-Soo
    [J]. RECENT ADVANCES IN E-ACTIVITIES, INFORMATION SECURITY AND PRIVACY, 2009, : 84 - +
  • [7] Effect of financial management practices on the development of small-to-medium size forest enterprises: insight from Pakistan
    Zada, Muhammad
    Cao Yukun
    Zada, Shagufta
    [J]. GEOJOURNAL, 2021, 86 (03) : 1073 - 1088
  • [8] Raytheon stresses value of small-to-medium enterprises
    Grevatt, Jon
    [J]. Jane's Defence Industry, 2006, (NOV.):
  • [9] Understanding Farmers' Data Collection Practices on Small-to-Medium Farms for the Design of Future Farm Management Information Systems
    Friedman, Natalie
    Tan, Zm
    Haskins, Micah N.
    Ju, Wendy
    Bailey, Diane
    Longchamps, Louis
    [J]. Proceedings of the ACM on Human-Computer Interaction, 2024, 8 (CSCW1)
  • [10] INFORMATION SYSTEMS FOR SMALL AND MEDIUM ENTERPRISES
    Democ, Vojtech
    Alac, Patrik
    [J]. AKTUALNE POHL'ADY NA KONKURENCIESCHOPNOST' A PODNIKANIE - NOVE VYZVY, 2011, : 79 - 84