AUTOMATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM BASED ON THE ISO/IEC 27001 STANDARD

被引:0
|
作者
de la Rosa Martin, Tonyse [1 ]
机构
[1] Univ Metropolitana, Quito, Ecuador
来源
REVISTA UNIVERSIDAD Y SOCIEDAD | 2021年 / 13卷 / 05期
关键词
ISO; security; information; automation; risk; system;
D O I
暂无
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
The present work aims to describe the requirements for the implementation and the necessary documentation of an Information Security Management System (ISMS). Automation consists of the availability of a template with internal control questions focused on the 3 pillars of information se-curity (confidentiality, integrity, availability) that allows a "Gap-Analysis" to be carried out to meas-ure the level of current maturity with respect to the requirements of the international standard ISO / IEC 27001: 2013, with a radar diagram and thus establish an ISMS or carry out the ISO 27001 certification process that guarantees to minimize risk and protect information on computers or in interconnected systems, since it is one of the most important assets of organizations, ensuring the confidentiality and integrity of the data and information of certain critical or sensitive processes, whose loss, leakage or unavailability of information puts problems in the organization.
引用
收藏
页码:495 / 506
页数:12
相关论文
共 50 条
  • [21] Information security and value creation: The performance implications of ISO/IEC 27001
    Podrecca, Matteo
    Culot, Giovanna
    Nassimbeni, Guido
    Sartor, Marco
    [J]. Computers in Industry, 2022, 142
  • [22] Der Standard ISO/IEC 27001:2013
    Kai Jendrian
    [J]. Datenschutz und Datensicherheit - DuD, 2014, 38 (8) : 552 - 557
  • [23] Extension of ISO/IEC27001 to Mobile Devices Security Management
    Zhu, Xiaobo
    Zhu, Yunqian
    [J]. CYBER SECURITY, CNCERT 2018, 2019, 970 : 27 - 35
  • [24] Analysis of factors that inhibiting implementation of Information Security Management System (ISMS) based on ISO 27001
    Tatiara, R.
    Fajar, A. N.
    Siregar, B.
    Gunawan, W.
    [J]. 2ND INTERNATIONAL CONFERENCE ON COMPUTING AND APPLIED INFORMATICS 2017, 2018, 978
  • [25] Customized Diagnostic Tool for The Security Maturity Level of The Enterprise Information Based on ISO/IEC 27001
    Lopez-Leyva, Josue A.
    Kanter-Ramirez, Christopher A.
    Morales-Martinez, Jose P.
    [J]. 2020 8TH EDITION OF THE INTERNATIONAL CONFERENCE IN SOFTWARE ENGINEERING RESEARCH AND INNOVATION (CONISOFT 2020), 2020, : 147 - 153
  • [26] INTEGRATION POSSIBILITIES OF ISO 9001:2008 QUALITY MANAGEMENT SYSTEM WITH ISO 27001:2010 INFORMATION SECURITY MANAGEMENT SYSTEM
    Britvic, Josip
    Kovacevic, Anita Prelas
    Cingel, Monika
    [J]. 2. MEDUNARODNI ZNANSTVENI SIMPOZIJ GOSPODARSTVO ISTOCNE HRVATSKE - JUCER, DANAS, SUTRA, 2013, : 368 - 373
  • [27] Risk assesment methods - ISO/IEC 27001 information security managament system's key element
    Luczak, Jacek
    [J]. SCIENTIFIC JOURNALS OF THE MARITIME UNIVERSITY OF SZCZECIN-ZESZYTY NAUKOWE AKADEMII MORSKIEJ W SZCZECINIE, 2009, 19 (91): : 63 - 70
  • [28] On Developing Information Security Management System (ISMS) Framework for ISO 27001-based Data Center
    Achmadi, Dedy
    Suryanto, Yohan
    Ramli, Kalamullah
    [J]. 2018 INTERNATIONAL WORKSHOP ON BIG DATA AND INFORMATION SECURITY (IWBIS), 2018, : 149 - 157
  • [29] INTEGRATION OF THE GDPR REQUIREMENTS INTO THE REQUIREMENTS OF THE SR EN ISO/IEC 27001:2018 STANDARD, INTEGRATION SECURITY MANAGEMENT SYSTEM IN A SOFTWARE DEVELOPMENT COMPANY
    Gaspar, Mirabela Luciana
    Popescu, Sorin Gabriel
    [J]. ACTA TECHNICA NAPOCENSIS SERIES-APPLIED MATHEMATICS MECHANICS AND ENGINEERING, 2018, 61 (03): : 85 - 96
  • [30] Using the bell labs security framework to enhance the ISO 17799/27001 information security management system
    Mcgee, Andrew R.
    Bastry, Frank A.
    Chandrashekhar, Uma
    Vasireddy, S. Rao
    Flynn, Lori A.
    [J]. BELL LABS TECHNICAL JOURNAL, 2007, 12 (03) : 39 - 54