A case study on the security audit methodologies in the context of information system's life cycle

被引:0
|
作者
Kim, J [1 ]
Hong, K [1 ]
机构
[1] Chung Ang Univ, Dept Informat Syst, Ansung, Kyunggi, South Korea
关键词
information security audit; information system security; process evaluation; control evaluation and information security evaluation;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Current information security management and audit methods are not effective enough to meet the increased corporate needs on information security. This paper attempts to compare, analyze, and apply to case study, some security audit and evaluation methods of Korea and other countries. In Korea, there is the Information Systems Security/Control Audit Guideline of NCA and the Information Security Management Systems Certification Guideline of KISA for information security audit. The SSE-CCM, BS 7799, NIST SP 800-26, and the ISG of ISACA are some of the better known criteria in other countries. The Information Systems Security/Control Audit Guideline of NCA, SSE-CCM and the ISG of ISACA are the process evaluation methods and the Information Security Management Systems Certification Guideline of KISA, BS 7799 and NIST SP 800-26 are the control evaluation methods. Based on application of the two major methods to a Korean case company, we conclude that process evaluation method needs to be more detailed and control evaluation method needs a modification of the levels of evaluation.
引用
收藏
页码:38 / 43
页数:6
相关论文
共 50 条
  • [31] STUDY ON INFORMATION SECURITY MANAGEMENT SYSTEM AND BUSINESS CONTINUITY MANAGEMENT IN THE CONTEXT OF THE GLOBAL CRISIS
    Lampe, Georg Sven
    Maftei, Mihaela
    Surugiu, Ioana
    Ionescu, Razvan Cristian
    [J]. 2020 BASIQ INTERNATIONAL CONFERENCE: NEW TRENDS IN SUSTAINABLE BUSINESS AND CONSUMPTION, 2020, : 942 - 949
  • [32] Life Cycle Perspective on Information System Technology
    Chesterman, C. W., Jr.
    Oliverio, Jared
    [J]. NAVAL ENGINEERS JOURNAL, 2015, 127 (03) : 97 - 108
  • [33] Functional Standardization of Life Cycle of Information System
    Boichenko, A. V.
    Lukinova, O. V.
    [J]. PROCEEDINGS OF THE 2016 CONFERENCE ON INFORMATION TECHNOLOGIES IN SCIENCE, MANAGEMENT, SOCIAL SPHERE AND MEDICINE (ITSMSSM), 2016, 51 : 255 - 258
  • [34] Applying soil quality indicators in the context of life cycle assessment in a Finnish case study
    Joensuu, Katri
    Saarinen, Merja
    [J]. INTERNATIONAL JOURNAL OF LIFE CYCLE ASSESSMENT, 2017, 22 (09): : 1339 - 1353
  • [35] Applying soil quality indicators in the context of life cycle assessment in a Finnish case study
    Katri Joensuu
    Merja Saarinen
    [J]. The International Journal of Life Cycle Assessment, 2017, 22 : 1339 - 1353
  • [36] Study on Information Security Experiment's Innovation and Practice Teaching System
    Cui Baojiang
    [J]. NATIONAL TEACHING SEMINAR ON CRYPTOGRAPHY AND INFORMATION SECURITY (2010NTS-CIS), PROCEEDINGS, 2010, : 438 - 441
  • [37] Context information based cyber security defense of protection system
    Su, Sheng
    Duan, Xianzhong
    Zeng, Xiangjun
    Chan, W. L.
    Li, K. K.
    [J]. 2007 IEEE POWER ENGINEERING SOCIETY GENERAL MEETING, VOLS 1-10, 2007, : 294 - 294
  • [38] Information System Security in the Context of Administrative Cooperation Through Internal Market Information System in Romania
    Stoian, Camelia Daciana
    Bucerzan, Dominic
    [J]. SOFT COMPUTING APPLICATIONS, SOFA 2016, VOL 2, 2018, 634 : 529 - 539
  • [39] Understanding cyberbullying as an information security attack-life cycle modeling
    Zambrano, Patricio
    Torres, Jenny
    Yanez, Angel
    Macas, Alexandra
    Tello-Oquendo, Luis
    [J]. ANNALS OF TELECOMMUNICATIONS, 2021, 76 (3-4) : 235 - 253
  • [40] Current Taxonomy of Information Security Threats in Software Development Life Cycle
    Barabanov, Alexander V.
    Markov, Alexey S.
    Grishin, Maksim I.
    Tsirlov, Valentin L.
    [J]. 2018 IEEE 12TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT), 2018, : 196 - 201