AUTOMATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM BASED ON THE ISO/IEC 27001 STANDARD

被引:0
|
作者
de la Rosa Martin, Tonyse [1 ]
机构
[1] Univ Metropolitana, Quito, Ecuador
来源
REVISTA UNIVERSIDAD Y SOCIEDAD | 2021年 / 13卷 / 05期
关键词
ISO; security; information; automation; risk; system;
D O I
暂无
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
The present work aims to describe the requirements for the implementation and the necessary documentation of an Information Security Management System (ISMS). Automation consists of the availability of a template with internal control questions focused on the 3 pillars of information se-curity (confidentiality, integrity, availability) that allows a "Gap-Analysis" to be carried out to meas-ure the level of current maturity with respect to the requirements of the international standard ISO / IEC 27001: 2013, with a radar diagram and thus establish an ISMS or carry out the ISO 27001 certification process that guarantees to minimize risk and protect information on computers or in interconnected systems, since it is one of the most important assets of organizations, ensuring the confidentiality and integrity of the data and information of certain critical or sensitive processes, whose loss, leakage or unavailability of information puts problems in the organization.
引用
收藏
页码:495 / 506
页数:12
相关论文
共 50 条
  • [1] NEW STANDARD ISO/IEC 27001:2013 OF INFORMATION SECURITY MANAGEMENT SYSTEM
    Drastich, Martin
    [J]. KNOWLEDGE FOR MARKET USE 2014: MEDIA AND COMMUNICATION IN THE 21ST CENTURY, 2014, : 387 - 393
  • [2] A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard
    Fonseca-Herrera, Omar A.
    Rojas, Alix E.
    Florez, Hector
    [J]. IAENG International Journal of Computer Science, 2021, 48 (02) : 1 - 10
  • [3] ADOPTION OF THE INFORMATION SECURITY MANAGEMENT SYSTEM STANDARD ISO/IEC 27001: A STUDY AMONG GERMAN ORGANIZATIONS
    Mirtsch, Mona
    [J]. INTERNATIONAL JOURNAL FOR QUALITY RESEARCH, 2023, 17 (03) : 747 - 768
  • [4] Information Security Risk Management: Handbook for ISO/IEC 27001
    Lomas, Elizabeth
    [J]. RECORDS MANAGEMENT JOURNAL, 2011, 21 (03) : 239 - +
  • [5] ADOPTION OF STANDARD FOR INFORMATION SECURITY ISO/IEC 27001 IN BOSNIA AND HERZEGOVINA
    Skopak, Anis
    Sakanovic, Semir
    [J]. INTERNATIONAL CONFERENCE ON ECONOMIC AND SOCIAL STUDIES (ICESOS'16): REGIONAL ECONOMIC DEVELOPMENT: ENTREPNEURSHIP AND INNOVATION, 2016, : 35 - 42
  • [6] Information security fortification by ontological mapping of the ISO/IEC 27001 standard
    Fenz, Stefan
    Goluch, Gernot
    Ekelhart, Andreas
    Riedl, Bernhard
    Weippl, Edgar
    [J]. 13TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2007, : 381 - +
  • [7] Information Security Management Systems - A Maturity Model Based on ISO/IEC 27001
    Proenca, Diogo
    Borbinha, Jose
    [J]. BUSINESS INFORMATION SYSTEMS (BIS 2018), 2018, 320 : 102 - 114
  • [8] Exploring the Adoption of the International Information Security Management System Standard ISO/IEC 27001: A Web Mining-Based Analysis
    Mirtsch, Mona
    Kinne, Jan
    Blind, Knut
    [J]. IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2021, 68 (01) : 87 - 100
  • [9] The ISO/IEC 27001 information security management standard: literature review and theory-based research agenda
    Culot, Giovanna
    Nassimbeni, Guido
    Podrecca, Matteo
    Sartor, Marco
    [J]. TQM JOURNAL, 2021, 33 (07): : 76 - 105
  • [10] Some Aspects Regarding the Information Security Management System within Organizations - Adopting the ISO/IEC 27001:2013 Standard
    Tiganoaia, Bogdan
    [J]. STUDIES IN INFORMATICS AND CONTROL, 2015, 24 (02): : 201 - 210