AUTOMATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM BASED ON THE ISO/IEC 27001 STANDARD

被引:0
|
作者
de la Rosa Martin, Tonyse [1 ]
机构
[1] Univ Metropolitana, Quito, Ecuador
来源
REVISTA UNIVERSIDAD Y SOCIEDAD | 2021年 / 13卷 / 05期
关键词
ISO; security; information; automation; risk; system;
D O I
暂无
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
The present work aims to describe the requirements for the implementation and the necessary documentation of an Information Security Management System (ISMS). Automation consists of the availability of a template with internal control questions focused on the 3 pillars of information se-curity (confidentiality, integrity, availability) that allows a "Gap-Analysis" to be carried out to meas-ure the level of current maturity with respect to the requirements of the international standard ISO / IEC 27001: 2013, with a radar diagram and thus establish an ISMS or carry out the ISO 27001 certification process that guarantees to minimize risk and protect information on computers or in interconnected systems, since it is one of the most important assets of organizations, ensuring the confidentiality and integrity of the data and information of certain critical or sensitive processes, whose loss, leakage or unavailability of information puts problems in the organization.
引用
收藏
页码:495 / 506
页数:12
相关论文
共 50 条
  • [41] Information security objectives and the output legitimacy of ISO/IEC 27001: stakeholders’ perspective on expectations in private organizations in Sweden
    Yasmin Kamil
    Sofia Lund
    M Sirajul Islam
    [J]. Information Systems and e-Business Management, 2023, 21 : 699 - 722
  • [42] Model Driven Information Security Management - Evaluating and Applying the Meta Model of ISO 27001
    Milicevic, Danijel
    Goeken, Matthias
    [J]. AMCIS 2011 PROCEEDINGS, 2011,
  • [43] Information security objectives and the output legitimacy of ISO/IEC 27001: stakeholders' perspective on expectations in private organizations in Sweden
    Kamil, Yasmin
    Lund, Sofia
    Islam, M. Sirajul
    [J]. INFORMATION SYSTEMS AND E-BUSINESS MANAGEMENT, 2023, 21 (03) : 699 - 722
  • [44] Developing an ISO27001 Information Security Management System for an Educational Institute: Hashemite University as a Case Study
    Itradat, Awni
    Sultan, Sari
    Al-Junaidi, Maram
    Qaffaf, Rawa'a
    Mashal, Feda'a
    Daas, Fatima
    [J]. JORDAN JOURNAL OF MECHANICAL AND INDUSTRIAL ENGINEERING, 2014, 8 (02): : 102 - 118
  • [45] Supporting the Development and Documentation of ISO 27001 Information Security Management Systems through Security Requirements Engineering Approaches
    Beckers, Kristian
    Fassbender, Stephan
    Heisel, Maritta
    Kuester, Jan-Christoph
    Schmidt, Holger
    [J]. ENGINEERING SECURE SOFTWARE AND SYSTEMS, 2012, 7159 : 14 - +
  • [46] Using Security Requirements Engineering Approaches to Support ISO 27001 Information Security Management Systems Development and Documentation
    Beckers, Kristian
    Fassbender, Stephan
    Heisel, Maritta
    Schmidt, Holger
    [J]. 2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 242 - 248
  • [47] Compliance with Saudi NCA-ECC based on ISO/IEC 27001
    Alsahafi, Tahani
    Halboob, Waleed
    Almuhtadi, Jalal
    [J]. TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2022, 29 (06): : 2090 - 2097
  • [48] Security Characteristic Evaluation Based On ISO/IEC 25023 Quality Model, Case Study: Laboratory Management Information System
    Aziz, M. Nasrul
    Sapta, Irit Maulana
    Rochimah, Siti
    [J]. 2018 ELECTRICAL POWER, ELECTRONICS, COMMUNICATIONS, CONTROLS, AND INFORMATICS SEMINAR (EECCIS), 2018, : 332 - 336
  • [49] Appraisal of Mask Manufacture Information Security Based on ISO27001 and Common Criteria
    Wang, Cynthia
    Guo, Eric
    Chen, Sammy
    Zhu, Sherry
    Wu, Jason
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEM), 2017, : 2317 - 2320
  • [50] A security requirement management database based on ISO/IEC 15408
    Morimoto, S
    Horie, D
    Cheng, JD
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 3, 2006, 3982 : 1 - 10